ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.
Affected Software
Event History
Frequently Asked Questions
Which Windows systems are exposed to this vulnerability?
Only affected Microsoft Windows installations that use specific IPsec configurations are vulnerable. The provided information does not identify the exact configurations or affected Windows versions.
Does an attacker need credentials or prior access?
No. Exploitation does not require authentication, so a remote attacker could attempt to exploit a vulnerable system without valid credentials.
What is the potential impact of successful exploitation?
A successful attacker can execute arbitrary code on the affected Windows installation.