CVE-2026-42904
Windows TCP/IP Elevation of Privilege Vulnerability
criticalEPSS 0.4 %
Beschreibung
Metriken
Severity
critical
92.53
kein öffentlicher PoC bekannt
9.6
Veröffentlicht
2026-06-09 07:00 UTC
CWE-122
Weakness-Klassen (CWE)
CWE-122Variant
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Translated2026-07-23 08:10 UTC· nvd@nist.gov
- Translation: Title: varias versiones de Windows, Description: Desbordamiento de búfer basado en montículo en TCP/IP de Windows permite a un atacante no autorizado elevar privilegios sobre una red adyacente.
Betroffene Betriebssysteme
windows
microsoft / windows_10_21h2
windows
microsoft / windows_10_22h2
windows
microsoft / windows_11_23h2
windows
microsoft / windows_11_24h2
windows
microsoft / windows_11_25h2
windows
microsoft / windows_11_26h1
windows
microsoft / windows_server_2022
windows
microsoft / windows_server_2025
Quellen & Referenzen
Verknüpfte Empfehlungen
IDCVE-2026-42904