CVE-2026-33824: Windows IKE Extensions Unauthenticated RCE via Double Free — Threadlinqs Intelligence
As of 2026-07-19, CVE-2026-33824: Windows IKE Extensions Unauthenticated RCE via Double Free is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-0365 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Updated: 2026-07-19 · revalidated 1× · latest source
Attribution: N/A · UNKNOWN
Critical unauthenticated remote code execution vulnerability in Windows Internet Key Exchange (IKE) Service Extensions. A double free condition (CWE-415) in IKEv2 packet processing allows attackers to
CVE-2026-33824 is a critical remote code execution vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions, specifically affecting IKEv2 implementations across all supported Windows versions. The vulnerability was disclosed and patched by Microsoft as part of the April 2026 Patch Tuesday release on April 14, 2026.
The root cause is a double free memory corruption flaw (CWE-415) in the ikeext service component (ikeext.dll) that handles IKEv2 key exchange negotiations for IPSec VPN tunnels. When the IKE service processes specially crafted network packets, it incorrectly attempts to free the same block of heap memory twice. This double free condition corrupts the heap allocator metadata, allowing an attacker to manipulate the state of the memory allocator and achieve arbitrary code execution.
The vulnerability carries maximum exploitability characteristics: it is network-accessible via UDP ports 500 (IKE) and 4500 (IKE NAT-Traversal), requires no authentication (pre-auth), requires no user interaction, and has low attack complexity. The CVSS v3.1 base score is 9.8 (Critical) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Successful exploitation grants the attacker SYSTEM-level privileges on the target host, as the IKEEXT service runs under the Local System account.
The attack surface is significant because IKE is a fundamental component of IPSec VPN infrastructure. Any Windows system running the IKEEXT service with IKEv2 enabled — including VPN gateways, domain controllers in site-to-site VPN configurations, and servers with IPSec transport mode policies — is potentially exposed. The service listens on UDP ports 500 and 4500, which must be accessible from the network for IPSec to function, making firewall-based mitigation challenging for organizations that depend on IKE/IPSec.
This vulnerability continues a pattern of critical IKE-related flaws in Windows. CVE-2022-34721, patched in September 2022, was a similar IKE Protocol Extensions RCE vulnerability that was addressed by adding length validation checks on incoming data. The IKEEXT service has also been the subject of historical DLL hijacking vulnerabilities affecting Windows Vista through Server 2012, where the service attempted to load non-existent DLLs.
Affected systems span a wide range of Windows versions: Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 22H2, 23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures. Microsoft released patches as part of the April 2026 Patch Tuesday update cycle with specific KB articles for each affected version.
As of disclosure, there is no evidence of active exploitation in the wild, no public proof-of-concept code, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Microsoft assesses exploitation as less likely in the latest software releases. However, the pre-authentication, network-accessible nature of the flaw makes it a high-priority patching target, as weaponization could enable wormable exploitation across enterprise networks.
Target sectors: government, defense, financial, critical-infrastructure, telecommunications, healthcare, energy, technology
Target regions: Global
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-33824, T1190, T1203, T1210, T1068, T1211, T1595, T1046, T1499, T1588, T1587