What the vendor says is affected
- Windows Server 2025 (Server Core installation)
- Windows 11 Version 25H2 for ARM64-based Systems
- Windows 11 Version 25H2 for x64-based Systems
- Windows 11 Version 24H2 for ARM64-based Systems
- Windows 11 Version 24H2 for x64-based Systems
- Windows Server 2025
- Windows 11 version 26H1 for x64-based Systems
- Windows 11 Version 26H1 for ARM64-based Systems
Versions the vendor lists as fixed
- 10.0.26100.33296
- 10.0.26100.33222
- 10.0.26200.9168
- 10.0.26200.9106
- 10.0.26100.9168
- 10.0.26100.9106
- 10.0.28000.2704
What the vendor recommends
The mitigation is disabled by default. To enable it, apply the following registry keys and reboot the machine. reg add HKLM\SYSTEM\CurrentControlSet\Services\Winnat /v TcpSeqValidation /t REG_DWORD /d 1 /f reg add HKLM\SYSTEM\CurrentControlSet\Services\Winnat /v TcpSeqRandomization /t REG_DWORD /d 1 /f Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5121000.
Review the complete instructions on the vendor's siteWhat changed in later vendor updates
SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.
- The vendor changed its remediation guidance.
When this advisory changed
- Published by Microsoft Security Response Center
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.
- Confirmed at the source
Our collector saw this advisory during a later source check.