CVE-2026-69588
Awaiting Analysis Awaiting Analysis - Queue

Memory Leak in Windows TCP/IP Stack

Vulnerability report for CVE-2026-69588, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: Microsoft Corporation

Description

Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-09
AI Q&A
2026-09-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
microsoft windows_tcp_ip *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-401 The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a missing release of memory after its effective lifetime in Windows TCP/IP. This flaw allows an unauthorized attacker to cause a denial of service over a network by exploiting the memory leak.

Impact Analysis

An attacker could exploit this to disrupt network services, leading to downtime or degraded performance for systems relying on Windows TCP/IP. This may affect availability of critical services.

Mitigation Strategies

Apply the latest Windows security updates from Microsoft to patch the TCP/IP memory release issue. Monitor network traffic for unusual patterns indicating denial of service attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69588. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart