critical Known exploitedREV. 01

CVE-2026-33824Windows Internet Key Exchange Service — Double Free to Code Execution

A double-free memory bug in the Windows Internet Key Exchange (IKE) service extension lets an unauthenticated attacker run code on the machine by sending crafted traffic over the network, with no user interaction needed.

YOUR NEXT MOVE

Install Microsoft's security update for the Windows Internet Key Exchange service on every Windows host now, and limit network exposure of the service until it is patched.

Read the risk

THE VITAL STATS
CVSS score
9.8/ 10
CVSS v3.1
EPSS probability
73%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Yes — CISA KEV
CVE published
2026-04-14
Added to KEV
2026-08-18
Exploit published
Not recorded
Confidence
medium
Kill chain
initial access
MITRE ATT&CK
T1190
Severity
critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attacker needsNetwork access to the Windows Internet Key Exchange service; no authentication or user interaction needed

Behind the card

4 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_atnvd.nist.gov2026-09-21scrty-crds-pipeline/0.1high
exploitation.known_exploited, exploitation.kev_addedcisa.gov2026-09-21scrty-crds-pipeline/0.1high
epssapi.first.org2026-09-21scrty-crds-pipeline/0.1high
title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisitesnvd.nist.gov2026-09-21claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2026-33824 · CRDS 0.1 · Issued 2026-09-21