• PATCH AVAILABLE

CVE-2026-72983: pre-auth remote code execution in Microsoft Windows 10 Version 1607

An unauthenticated attacker can execute arbitrary code over the network against Windows systems that expose Internet Connection Sharing (ICS). CVE-2026-72983 is a use-after-free flaw in ICS that allows remote code execution. Affected builds include multiple Windows 10 branches (for example Windows 10 Version 1607: 10.0.14393.0 through before 10.0.14393.9512) as well as several Windows 11 and Windows Server 2012 builds; an attacker needs only network access — no credentials or user interaction — to exploit the bug.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a network unauthenticated remote code execution — an attacker only needs network access (no login), so prioritize deploying the provided fixes or otherwise isolating ICS-exposed hosts.

What is CVE-2026-72983?

An unauthenticated attacker can execute arbitrary code over the network against Windows systems that expose Internet Connection Sharing (ICS). CVE-2026-72983 is a use-after-free flaw in ICS that allows remote code execution. Affected builds include multiple Windows 10 branches (for example Windows 10 Version 1607: 10.0.14393.0 through before 10.0.14393.9512) as well as several Windows 11 and Windows Server 2012 builds; an attacker needs only network access — no credentials or user interaction — to exploit the bug. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-72983 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-72983

  1. Apply Microsoft updates that contain the fixes for the affected branches (for example 10.0.14393.9512 and later for Windows 10 Version 1607).
  2. Identify hosts running Internet Connection Sharing and update them to the fixed builds listed by the vendor.
  3. Restrict network exposure of ICS services using firewall rules and network segmentation for internet-facing or untrusted networks.
  4. Monitor affected hosts for suspicious activity and review network logs for unexpected connections to ICS services.

Frequently asked questions

Is CVE-2026-72983 being actively exploited?

There are no public reports of active exploitation of CVE-2026-72983 as of 2026-09-29.

Which Windows 10 Version 1607 versions are affected by CVE-2026-72983?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are affected; 10.0.14393.9512 is the fixed build.

Is there a patch for CVE-2026-72983?

Yes. Microsoft published fixed builds for the listed branches (for example 10.0.14393.9512 for Windows 10 Version 1607 and corresponding fixed builds for other affected releases).

Does CVE-2026-72983 require authentication?

No. The vulnerability in Windows Internet Connection Sharing can be exploited over the network without authentication or user interaction.

References