ZDI-CAN-31212: ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Affected Microsoft Windows installations are exposed only when they use specific IPsec configurations. The available information does not identify the exact configurations or affected Windows versions.
Does an attacker need credentials or prior access?
No. Exploitation does not require authentication, so a remote attacker could target a vulnerable system without credentials.
What is the potential impact of successful exploitation?
A successful attacker can execute arbitrary code on an affected installation of Microsoft Windows.