Impact
The vulnerability is an origin‑validation error in Windows Network Address Translation (NAT). Because the NAT implementation does not sufficiently verify the source address of each packet, an attacker can forge the original source of traffic. This spoofing allows the attacker to elect virtual addresses that belong to legitimate hosts or services, thereby enabling the masquerade of legal traffic and potentially bypassing security controls that rely on accurate source identification.
Affected Systems
Microsoft Windows 11 version 24H2, 25H2, and 26H1, including ARM64 and x64 builds, and Microsoft Windows Server 2025 both in its full and Server Core installation modes are affected.
Risk and Exploitability
The CVSS score of 8.3 places the flaw in the high‑severity range, while the EPSS score of fewer than 1% indicates that large‑scale exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to be on the same local network or an adjacent network segment and to be able to send crafted packets that bypass NAT origin checks. The likely attack vector is local network traffic that can be redirected or spoofed by a malicious host in a nearby LAN or subnet.
OpenCVE Enrichment