Impact
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. The CVE description was updated, but specific changes are not reflected in the current data.
Affected Systems
Affected are Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, 2025, and their Server Core installations. These systems run the UPnP Device Host service that contains the vulnerable upnp.dll.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score of < 1% indicates a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based; an adversary must reach the target’s UPnP interface, which opens a defensive need for network perimeter controls or disabling the service if it is not required. Patching removes the risk entirely.
OpenCVE Enrichment