Impact
An unauthorized attacker can trigger a use‑after‑free in the Universal Plug and Play (upnp.dll) component of Windows. The flaw permits arbitrary code execution over a network connection, allowing full compromise of the host system. The vulnerability is a classic memory corruption weakness categorized as CWE‑843.
Affected Systems
Affected are Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, 2025, and their Server Core installations. These systems run the UPnP Device Host service that contains the vulnerable upnp.dll.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based; an adversary must reach the target’s UPnP interface, which opens a defensive need for network perimeter controls or disabling the service if it is not required. Patching removes the risk entirely.
OpenCVE Enrichment