Impact
An origin validation error in the Windows Network Address Translation (NAT) component allows an attacker who is not authorized to spoof IP addresses on a network adjacent to the vulnerable host. Because the NAT layer fails to verify the source of packets properly, the attacker can inject traffic that appears to come from legitimate internal addresses. This flaw is classified as CWE‑346, reflecting insufficient input validation. An attacker who succeeds can forge traffic that may be accepted by downstream hosts, enabling man‑in‑the‑middle sessions, IP address spoofing, or potentially the execution of commands directed at internal systems.
Affected Systems
Microsoft Windows 11 build 24H2, 25H2, and 26H1, including both arm64 and x64 architectures, and Microsoft Windows Server 2025, including the standard and Server Core editions, are affected.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that active exploitation is currently unlikely, and the issue is not listed in the CISA KEV catalog. Inferred from the description, the likely attack vector is an adversary having network connectivity to the same subnet or VLAN as the target, either from a physically connected device or a compromised local host, and capable of sending crafted packets to the NAT service. The flaw requires no privileged local access, so it can be exploited remotely in the sense of being on the adjacent network, but it does not provide systemic escalation beyond the local network segment.
OpenCVE Enrichment