Who is affected
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability allowing remote code execution. The record does not specify which versions of Windows or which deployment configurations are vulnerable, nor whether on-premises and cloud deployments are equally affected. You are affected if you operate IKE Service Extensions in your environment.
How to check whether this touches you
- Inventory check: Confirm whether IKE Service Extensions is installed and enabled on any Windows systems you manage. Check Group Policy, system configuration, and VPN or IPsec gateway deployments.
- Reachability: If IKE Service Extensions is exposed on network interfaces reachable from untrusted networks (including the internet), the attack surface is highest. Determine whether your IKE endpoints are restricted to internal or partner networks only.
- Version fingerprinting: Obtain the version numbers of IKE Service Extensions from affected systems. Consult Microsoft's security advisory to map your versions against the vulnerable range; note that some backported patches may complicate version-based assessment.
- Usage context: Identify whether IKE Service Extensions is actively used for VPN, remote access, or site-to-site connectivity, or whether it is installed but dormant.
What to do
- Obtain Microsoft's official guidance immediately. Microsoft will publish a security advisory and patch availability. Retrieve the specific remediation steps from Microsoft's security update page for CVE-2026-33824.
- If you cannot patch within the federal deadline (21 August 2026), apply Microsoft's interim mitigations without delay. These may include disabling the service, restricting network access via firewall rules, or applying workarounds; follow Microsoft's instructions precisely.
- Reduce reachability. If IKE Service Extensions is internet-facing, restrict access to authorised peer IP addresses and consider moving VPN endpoints behind a bastion or load balancer if architecture permits.
- Enable logging. Configure audit logging on IKE Service Extensions and upstream firewalls to capture connection attempts, especially any that fail or appear anomalous.
- Plan patching. Align your patch deployment with CISA's BOD 26-04 guidance, prioritising internet-exposed systems and critical infrastructure. Test patches in a staging environment before production rollout.
- Escalate if mitigations are unavailable. If Microsoft does not provide a patch or workaround by the remediation deadline, engage your Chief Information Security Officer and evaluate whether discontinuing use of IKE Service Extensions is feasible for your operations.
If you find you were exposed
Exploitation of a double free vulnerability typically requires network proximity and does not leave obvious application-level traces. Review firewall and VPN gateway logs from before the record publication date (18 August 2026) for anomalous IKE traffic, failed authentications, or service crashes that might indicate exploitation attempts. Retain at least 90 days of logs if you have not already done so; older logs may have been rotated out, limiting retrospective visibility.