Microsoft Windows TCPIP.SYS IppQualifyAddresses Out-of-Bounds Read Vulnerability
TALOS-2026-2427 CVE-2026-49177 An out-of-bounds read vulnerability exists in the IppQualifyAddresses function of the Microsoft Windows tcpip.sys driver. A specially crafted I/O request packet (IRP) can cause an arbitrary out-of-bounds read, potentially leading to information disclosure or a denial-of-service condition. The versions below were either tested or verified to be vulnerable […]
