CVE-2026-49177
Analyzed Analyzed - Analysis Complete

Out-of-Bounds Read in Windows TCP/IP

Vulnerability report for CVE-2026-49177, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-49177 is an out-of-bounds read vulnerability in the Windows TCP/IP stack. This flaw allows an authorized attacker with local access to the system to read memory outside the intended boundaries, potentially disclosing sensitive information.

The vulnerability is classified as an information disclosure issue, meaning it does not allow code execution or privilege escalation but can expose confidential data stored in memory.

  • Affected component: Windows TCP/IP stack.
  • Attack vector: Local (AV:L), meaning the attacker must have access to the target system.
  • Privilege requirement: Low (PR:L), indicating the attacker needs some level of authorization but not administrative rights.
Detection Guidance

The provided context does not include specific detection methods or commands for identifying the out-of-bounds read vulnerability in Windows TCP/IP (CVE-2026-49177). Detection typically requires checking for the presence of the vulnerable component or using security tools that can identify anomalous behavior related to TCP/IP processing.

For accurate detection guidance, refer to Microsoft's official documentation or security updates, which may provide details on how to verify if your system is affected.

Impact Analysis

This vulnerability can impact you in the following ways:

  • Information disclosure: An attacker with local access to your system could exploit this flaw to read sensitive data from memory, such as passwords, encryption keys, or other confidential information.
  • Potential for further attacks: While the vulnerability itself does not allow code execution, the disclosed information could be used to facilitate additional attacks, such as privilege escalation or lateral movement within a network.
  • System integrity risk: If sensitive data is exposed, it could lead to unauthorized access to other systems or services, compromising the security of your environment.
Compliance Impact

This vulnerability can affect compliance with common standards and regulations in the following ways:

  • GDPR: If the disclosed information includes personal data of EU citizens, this vulnerability could lead to a breach of GDPR requirements. GDPR mandates the protection of personal data, and failure to mitigate such vulnerabilities could result in non-compliance, fines, or legal action.
  • HIPAA: For organizations handling protected health information (PHI), this vulnerability could result in unauthorized disclosure of PHI. HIPAA requires safeguards to protect PHI, and exploitation of this flaw could violate those requirements, leading to penalties.
  • Other standards: Compliance frameworks like ISO 27001, NIST, or PCI DSS emphasize the importance of protecting sensitive data. This vulnerability could indicate a failure to implement adequate security controls, potentially leading to non-compliance with these standards.

Organizations should assess whether the vulnerability exposes regulated data and take appropriate steps to mitigate the risk, such as applying patches or implementing compensating controls.

Mitigation Strategies

To mitigate CVE-2026-49177, apply the security update provided by Microsoft as soon as possible. The update will address the out-of-bounds read issue in Windows TCP/IP.

  • Visit the Microsoft Update Guide for CVE-2026-49177 to download and install the patch.
  • Ensure all Windows systems are up to date with the latest security patches.
  • Restrict local access to authorized users only, as the vulnerability requires local access to exploit.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49177. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart