Vulnerability record · CVE-2023-21758 · published 10 January 2023
CVE-2023-21758: Windows IKE Extension NULL Pointer Dereference Denial of Service
Microsoft · Windows 10
CVE-2023-21758 is a denial of service flaw in the Windows Internet Key Exchange (IKE) extension, mapped to CWE-476 (NULL pointer dereference) with NVD also noting insufficient information. A remote, unauthenticated attacker can trigger the fault over the network, making it relevant to any internet-exposed or IKE-reachable Windows host. The record gives no root-cause detail beyond the flaw class, so the exact trigger path is not documented here.
Description
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityHigh CVSS (7.5) with network-reachable, unauthenticated, no-interaction trigger and a very high EPSS score, though impact is limited to denial of service and no KEV listing exists.
What it is
CVE-2023-21758 is a denial of service flaw in the Windows Internet Key Exchange (IKE) extension, mapped to CWE-476 (NULL pointer dereference) with NVD also noting insufficient information. A remote, unauthenticated attacker can trigger the fault over the network, making it relevant to any internet-exposed or IKE-reachable Windows host. The record gives no root-cause detail beyond the flaw class, so the exact trigger path is not documented here.
Impact
Successful exploitation causes a denial of service; the CVSS vector shows availability impact only (A:H) with no confidentiality or integrity loss. The attacker gains service disruption, not code execution or data access.
Attack surface
Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), consistent with an IKE/IPsec endpoint processing remote packets. Any host running the affected Windows versions with IKE exposed is in scope.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high at 0.925 (99.8th percentile), indicating elevated predicted exploitation activity. The two references are Microsoft update-guide pages with no exploit tags, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Apply the Microsoft security update for CVE-2023-21758 to all affected Windows 10, Windows 11, Windows Server 2016, 2019 and 2022 systems.
- Restrict IKE/UDP 500 and 4500 exposure to trusted networks; do not leave IKE reachable from the public internet where avoidable.
- Segment and firewall IPsec endpoints so only expected peers can send IKE traffic.
- Monitor vendor advisories for updated guidance and re-check affected builds after patching.
Detection
- Monitor for IKE service crashes, restarts or unexpected termination on Windows hosts (service and system event logs).
- Alert on spikes or anomalies in inbound UDP 500/4500 traffic to Windows endpoints.
- Correlate host availability gaps with IKE-related process faults to distinguish this DoS from other outages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-21758 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-21758), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.