Microsoft Windows TCP/IP Null Pointer Dereference Vulnerability Leading to Denial of Service

Vulnerability

A null pointer dereference vulnerability has been identified in the Windows TCP/IP stack. This issue allows an unauthorized attacker to cause a denial of service on the affected system, with the vulnerability being exploitable from an adjacent network. The problem arises from the way the TCP/IP stack handles certain network traffic, leading to a crash or unresponsiveness of the system.

Impact

Exploitation of this vulnerability causes a denial-of-service condition, where the affected system becomes unresponsive or fails to function properly. In the case of Windows Server 2022, 23H2 Edition (Server Core installation), the denial-of-service impact extends to the Hyper-V host environment, affecting all running virtual machines.

Remediation

Users can apply the security update provided by Microsoft to address this vulnerability. This security update is available through the Microsoft Update Catalog. For specific guidance on downloading and installing the update, refer to the Microsoft Knowledge Base articles associated with the vulnerability.

Added: May 12, 2026, 7:29 PM
Updated: May 12, 2026, 7:29 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
3.3
exploitability
4.7
remediation
7.7
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.