Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Fixed in 10.0.14393.9060, 10.0.17763.8644, 10.0.19044.7184, 10.0.19045.7184 — upgrade to this release or later.
  • CVEs: CVE-2026-33824.

What it is

CVE-2026-33824 is a double-free vulnerability in the Windows IKE (Internet Key Exchange) Extension. IKE is the component that negotiates and manages IPsec security associations, so it sits directly on the network-facing path for any host that has IPsec enabled or listening.

The flaw allows an unauthorised attacker to execute code over the network — no credentials and no user interaction are required. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms this is a remotely reachable, low-complexity attack against the IPsec/IKE service itself, not an authenticated management interface. A double free of this kind typically corrupts heap memory, and here that corruption is exploitable to run arbitrary code with the privileges of the IKE Extension process.

This is a full compromise scenario: confidentiality, integrity and availability are all rated high impact. The vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 18 August 2026, so it is known to be exploited.

What to do

  • Patch immediately. Microsoft has published fixed builds per Windows version, including 10.0.14393.9060, 10.0.17763.8644, 10.0.19044.7184, 10.0.19045.7184, 10.0.20348.5020, 10.0.22631.6936, 10.0.25398.2274, 10.0.26100.8246, 10.0.26100.32690, 10.0.26200.8246 and 10.0.28000.1836 — match against your installed build and deploy the corresponding update.
  • Treat this as a KEV-listed vulnerability requiring urgent remediation, particularly on any host with IPsec/IKE exposed to untrusted networks.
  • Where patching cannot happen immediately, restrict inbound access to the IKE/IPsec ports (UDP 500 and 4500) at the network boundary to trusted peers only, as a temporary compensating control.
  • After patching, confirm the installed build number matches or exceeds the fixed version for your specific Windows release — version numbering differs across Windows 10, Windows 11 and Server builds, so check per host rather than assuming a single patch covers the estate.

For leadership 🧭

Executive summary. Any Windows host with IPsec/IKE reachable from an untrusted network can be fully compromised without credentials or user interaction, and active exploitation is already confirmed via CISA’s KEV listing. This needs emergency patching this week, not at the next routine cycle.

Why it matters:

  • The flaw sits in the IKE Extension itself, which negotiates IPsec security associations on the network-facing path — no VPN client interaction or authentication is needed to trigger it.
  • CVSS 9.8 with full confidentiality, integrity and availability impact means successful exploitation gives an attacker code execution with the privileges of the IKE Extension process, not just a crash.
  • CISA added this to the Known Exploited Vulnerabilities catalogue on 18 August 2026, meaning it is already being used against real targets, not a theoretical risk.
  • Fixed builds are version-specific across Windows 10, Windows 11 and Server, so a single patch pass will not cover a mixed estate — each host needs its build number checked individually.

Now / Next / Later:

  • Now: Identify every host with IPsec/IKE enabled or reachable on UDP 500/4500 and check whether it is exposed to untrusted networks.
  • Next: Deploy the matching fixed build for each Windows version in your estate — the correct target build differs by release, so patch per-host rather than assuming one update covers everything.
  • Later: Restrict inbound UDP 500/4500 at the network boundary to known IPsec peers as standing policy, so IKE is never left open to arbitrary untrusted traffic between patch cycles.

Source