CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-33824: Remote Code Execution in Windows IKEv2

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 395

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-33824: Remote Code Execution in Windows IKEv2

A double-free vulnerability in Windows IKEv2 service allows an unauthenticated remote attacker to crash the IKEEXT service or achieve arbitrary code execution by sending crafted Internet Key Exchange packets. The flaw occurs during fragment reassembly when a Security Realm Vendor ID payload causes improper pointer ownership handling in memory, leading to the same heap allocation being freed twice. Microsoft's WARP and MORSE team discovered this vulnerability, which has been patched.

Why it matters: Unauthenticated remote code execution on Windows systems via VPN infrastructure warrants immediate patching if systems are exposed to untrusted networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-33824: Remote Code Execution in Windows IKEv2

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-33824: Remote Code Execution in Windows IKEv2

Researchers disclosed a double‑free flaw in the Windows Internet Key Exchange version 2 (IKEv2) service that could be exploited remotely. The vulnerability permits an unauthenticated attacker to crash the IKEEXT service or achieve arbitrary code execution by sending specially crafted IKEv2 fragments. Microsoft has released a patch addressing the issue in all supported Windows versions.

Why it matters: Windows administrators should apply the Microsoft patch to prevent unauthenticated remote code execution or denial‑of‑service on systems running the IKEv2 service.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-33824: Remote Code Execution in Windows IKEv2

Researchers disclosed a double‑free flaw in the Windows Internet Key Exchange version 2 (IKEv2) service that could be exploited remotely. The vulnerability permits an unauthenticated attacker to crash the IKEEXT service or achieve arbitrary code execution by sending specially crafted IKEv2 fragments. Microsoft has released a patch addressing the issue in all supported Windows versions.

Why it matters: Windows administrators should apply the Microsoft patch to prevent unauthenticated remote code execution or denial‑of‑service on systems running the IKEv2 service.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary