CVE-2026-62815: Microsoft QUIC Remote Code Execution Vulnerability
Summary Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Details
New network path creations and removals triggered by incoming packets can lead to a pointer invalidation.
Patches
- Guard path promotion e0f55b5
Impact
An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.
Other sources
Microsoft QUIC Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33296Fixed in 10.0.26100.33222Patch KB5120228 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2704Patch KB5121000 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5499Fixed in 10.0.20348.5440Patch KB5120229 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7517Patch KB5120240 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.9168Fixed in 10.0.26200.9106Patch KB5120994 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9168Fixed in 10.0.26200.9106Patch KB5120994 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9168Fixed in 10.0.26100.9106Patch KB5120994 - Upgrade
Upgrade
nuget/Microsoft.Native.Quic.MsQuic.Schannelto a version that resolves this vulnerability.Fixed in 2.4.19 - Upgrade
Upgrade
nuget/Microsoft.Native.Quic.MsQuic.OpenSSLto a version that resolves this vulnerability.Fixed in 2.4.19 - Upgrade
Upgrade
nuget/Microsoft.Native.Quic.MsQuic.Schannelto a version that resolves this vulnerability.Fixed in 2.5.10 - Upgrade
Upgrade
nuget/Microsoft.Native.Quic.MsQuic.OpenSSLto a version that resolves this vulnerability.Fixed in 2.5.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62815?
CVE-2026-62815 has a critical severity rating of 9.8.
How can I mitigate CVE-2026-62815?
To mitigate CVE-2026-62815, ensure that your Microsoft Windows systems are updated with the latest security patches.
What systems are affected by CVE-2026-62815?
CVE-2026-62815 affects Microsoft Windows 11, Windows Server 2025, and Windows Server 2022.
What type of vulnerability is CVE-2026-62815?
CVE-2026-62815 is classified as a Use After Free vulnerability which can lead to remote code execution.
What impact does CVE-2026-62815 have on affected systems?
CVE-2026-62815 allows unauthorized attackers to execute code remotely on affected systems over a network.