CVE-2026-33824: Windows IKE Double-Free: Wormable CVSS 9.8 RCE

By Parth Shukla · 2026-04-17

CVE-2026-33824: Windows IKE double-free enabling wormable CVSS 9.8 RCE. No auth required. Detect exposure and apply Microsoft patches.

#cve #microsoft #windows #rce #wormable

Frequently asked questions

What is CVE-2026-33824?

CVE-2026-33824 is a double-free vulnerability (CWE-415) in the Windows Internet Key Exchange and AuthIP IP Security Keying Modules service, known as IKEEXT. IKEEXT manages IKEv1 and IKEv2 key exchanges for IPsec connections — it's the component that authenticates and establishes the cryptographic channels for Windows VPN and IPsec policies.

Is CVE-2026-33824 being actively exploited?

As of April 17, 2026, CVE-2026-33824 has not been added to the CISA Known Exploited Vulnerabilities catalog and Microsoft has not confirmed exploitation in the wild at the time of patching. Microsoft classified the exploitability as "Exploitation More Likely" — their terminology for vulnerabilities where they assess that working exploit code could be built in the near term and that attackers are likely to use it.

Am I exposed to CVE-2026-33824?

Any Windows system with the IKEEXT service enabled is in scope. That service is active by default on systems configured for:

How do I fix CVE-2026-33824?

The only definitive fix is the cumulative security update released on April 14, 2026 as part of Microsoft's April Patch Tuesday. Install via Windows Update, WSUS, or the Microsoft Update Catalog. The update is available for all affected Windows 10, Windows 11, and Windows Server versions listed above.

Check your own attack surface with Pinaka