Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-69881Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A null pointer dereference vulnerability in Windows Internet Key Exchange (IKE) Extension allows an unauthenticated remote attacker to send a specially crafted network packet that causes a denial of service condition by crashing the IKE service. This affects Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2019, 2022, and 2025. Microsoft has released fixes for all affected versions. Exploitation is unlikely in the wild but the vulnerability can disrupt IPsec-based VPN connectivity.

What this means
What could happen
A remote attacker can crash the Windows IKE (Internet Key Exchange) service by sending a specially crafted network packet, causing IPsec VPN connections to drop and potentially disrupting any remote access or site-to-site connectivity that relies on IPsec encryption.
Who's at risk
Organizations using Windows 10, Windows 11, or Windows Server 2019, 2022, or 2025 systems that have IPsec VPN or IKE services enabled. This includes remote workers connecting via VPN, branch offices with site-to-site tunnels, and any infrastructure relying on IPsec for encrypted communications.
How it could be exploited
An attacker sends a malformed IKE packet to a Windows device over the network (typically UDP port 500 or 4500). The packet triggers a null pointer dereference in the IKE Extension component, crashing the IKEsvc.exe service and dropping any active VPN sessions.
Prerequisites
  • Network access to the Windows device on UDP port 500 or 4500 (IKE protocol ports)
  • IPsec/IKE service must be enabled and listening on the network
remotely exploitableno authentication requiredlow complexityaffects VPN/secure communications
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/11
Do now
0/1
WORKAROUNDRestrict network access to UDP ports 500 and 4500 to only trusted remote offices or VPN gateways via firewall rules
Schedule — requires maintenance window
0/10

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 (including Server Core) to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 (including Server Core) to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1809 32-bit systems to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1809 x64 systems to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7725 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7725 or later
HOTFIXUpdate Windows 11 Version 23H2 to Build 10.0.22631.7582 or later
HOTFIXUpdate Windows 11 Version 24H2 to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 to Build 10.0.26200.9445 or later
API: /api/v1/advisories/741ad9e1-325d-4edd-a310-88d025d46194

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | CVSS 7.5 - OTPulse