CRITICAL
CVE-2026-33824
CVSS
9.8
KEV
Description
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Summary dbcve.org
A double-free vulnerability exists in the Windows IKE (Internet Key Exchange) Extension, which is part of Windows IPsec implementation. The double-free condition can be triggered by an unauthenticated remote attacker sending specially crafted network packets, potentially leading to arbitrary code execution with elevated privileges.
Mitigation
Apply Microsoft security patches for Windows systems running IKE Extension services. Disable IKE if not required, or restrict network access to VPN gateways to limit attack surface.
Weakness (CWE)
CWE-415
Double Free
EPSS Score
72.7%
Probability of exploitation in next 30 days
99.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.