PT-2026-32883 · Microsoft · Windows 10+1
Published
2026-04-14
·
Updated
2026-05-16
·
CVE-2026-33824
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 10 Version 1607 versions 10.0.14393.0 through 10.0.14393.9059
Description
A double free issue exists in the Windows IKE Extension. This flaw allows an unauthorized remote attacker to trigger memory corruption in the IKE service extensions, potentially leading to arbitrary code execution over the network with SYSTEM privileges. The issue affects IKEv2 and requires no authentication or user interaction.
Recommendations
Update Microsoft Windows 10 Version 1607 to version 10.0.14393.9060 or later.
Fix
RCE
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10