PT-2026-32883 · Microsoft · Windows 10+1

Published

2026-04-14

·

Updated

2026-05-16

·

CVE-2026-33824

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows 10 Version 1607 versions 10.0.14393.0 through 10.0.14393.9059
Description A double free issue exists in the Windows IKE Extension. This flaw allows an unauthorized remote attacker to trigger memory corruption in the IKE service extensions, potentially leading to arbitrary code execution over the network with SYSTEM privileges. The issue affects IKEv2 and requires no authentication or user interaction.
Recommendations Update Microsoft Windows 10 Version 1607 to version 10.0.14393.9060 or later.

Fix

RCE

Double Free

Weakness Enumeration

Related Identifiers

BDU:2026-05343
CVE-2026-33824

Affected Products

Windows
Windows 10