CRITICAL

CVE-2026-33824

Microsoft Windows 10 1607 2026-04-14 CVSS v3.1
CVSS
9.8
KEV

Description

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Summary dbcve.org

A double-free vulnerability exists in the Windows IKE (Internet Key Exchange) Extension, which is part of Windows IPsec implementation. The double-free condition can be triggered by an unauthenticated remote attacker sending specially crafted network packets, potentially leading to arbitrary code execution with elevated privileges.

Mitigation

Apply Microsoft security patches for Windows systems running IKE Extension services. Disable IKE if not required, or restrict network access to VPN gateways to limit attack surface.

Weakness (CWE)

CWE-415 Double Free

EPSS Score

72.7%
Probability of exploitation in next 30 days
99.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE