CVE-2026-69588: Windows TCP/IP Denial of Service Vulnerability
Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
Other sources
Windows TCP/IP Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33438Patch KB5122871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9445Patch KB5124008 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2954Patch KB5124012 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.9445Patch KB5124008 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7582Patch KB5122880 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5622Patch KB5122882
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An unauthorized attacker can exploit it remotely over a network. No privileges or user interaction are required according to the supplied vector.
What is the expected impact of a successful attack?
A successful attack can deny service by triggering memory that is not released after its effective lifetime in Windows TCP/IP. The supplied metrics indicate availability impact, with no stated confidentiality or integrity impact.
Which products are identified as affected?
The listed affected software is Microsoft Windows 11, Microsoft Windows Server 2025, and Microsoft Windows Server 2022.