Vulnerability record · CVE-2023-21547 · published 10 January 2023
CVE-2023-21547: Windows IKE Protocol NULL Pointer and Resource Exhaustion DoS
Microsoft · Windows 10 1607
CVE-2023-21547 is a denial of service flaw in the Windows implementation of the Internet Key Exchange (IKE) protocol, rooted in a NULL pointer dereference and uncontrolled resource consumption. Because IKE is reachable over the network without credentials, an unauthenticated remote attacker can disrupt IKE-dependent services on affected Windows systems. The record gives no detail on the specific packet or code path involved.
Description
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated network-reachable availability impact across a broad set of current Windows versions, with very high EPSS despite no KEV listing.
What it is
CVE-2023-21547 is a denial of service flaw in the Windows implementation of the Internet Key Exchange (IKE) protocol, rooted in a NULL pointer dereference and uncontrolled resource consumption. Because IKE is reachable over the network without credentials, an unauthenticated remote attacker can disrupt IKE-dependent services on affected Windows systems. The record gives no detail on the specific packet or code path involved.
Impact
An attacker can cause a denial of service, degrading or halting IKE/IPsec functionality on the target host. There is no confidentiality or integrity impact per the CVSS vector; only availability is affected.
Attack surface
Reached over the network via the IKE protocol (UDP 500/4500) with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any Windows host with IKE/IPsec services exposed to untrusted networks is in scope.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high at 0.89276 (99.77th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply the Microsoft security update for CVE-2023-21547 on all affected Windows 10, Windows 11, Windows Server 2016, 2019 and 2022 systems.
- Restrict inbound IKE (UDP 500/4500) to trusted peers at the perimeter and host firewall where IPsec is not required from the internet.
- Disable or stop the IKEEXT service on hosts that do not use IPsec VPN functionality.
- Monitor for repeated IKE negotiation failures or service restarts and rate-limit IKE traffic from untrusted sources.
- Verify patch status across all listed product versions, since the affected list spans multiple Windows 10 and 11 builds and server releases.
Detection
- Alert on IKEEXT service crashes, restarts or unexpected stops in the Windows System event log.
- Monitor for spikes or malformed patterns in inbound UDP 500/4500 traffic to Windows hosts.
- Correlate host availability drops or IPsec tunnel failures with concurrent IKE traffic anomalies.
- Track EPSS and vendor advisories for signs of in-the-wild exploitation given the high predicted probability.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-21547 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-21547), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.