Description
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free bug within Microsoft NAT Helper Components (ipnathlp.dll) that permits an authorized local attacker to gain higher privileges on the affected system. Because the flaw is triggered by a specific memory condition after a component has been freed, the attacker can execute arbitrary code with elevated rights, potentially compromising system integrity and confidentiality. The weakness is classified as CWE‑416 (Use After Free).

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, and 26H1 (ARM64 and x64 architectures) as well as the Windows Server operating systems provide the native NAT helper component that contains the flaw.

Risk and Exploitability

The CVSS score is 7.8, indicating high severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. An attacker must already have local or authorized privileges to trigger the use‑after‑free condition; precise timing within ipnathlp.dll is required. Despite the low exploitation likelihood, the severity warrants prompt mitigation.

Generated by OpenCVE AI on July 31, 2026 at 06:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update cited in the Microsoft Security Response Center for CVE‑2026‑58537.
  • Disable or uninstall ipnathlp.dll by configuring Group Policy or registry to prevent the NAT helper service from loading.
  • Ensure that local accounts are limited to the least privileged accounts necessary, removing any unnecessary administrative or elevated roles.

Generated by OpenCVE AI on July 31, 2026 at 06:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.
Title Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:58:50.959Z

Reserved: 2026-07-01T04:33:41.870Z

Link: CVE-2026-58537

cve-icon Vulnrichment

Updated: 2026-07-16T14:25:29.274Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:15:04Z

Weaknesses