Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
New network path creations and removals triggered by incoming packets can lead to a pointer invalidation.
An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.
{
"cwe_ids": [
"CWE-416"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-08T20:27:02Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}