Impact
The vulnerability is a use‑after‑free bug within Microsoft NAT Helper Components (ipnathlp.dll) that permits an authorized local attacker to gain higher privileges on the affected system. Because the flaw is triggered by a specific memory condition after a component has been freed, the attacker can execute arbitrary code with elevated rights, potentially compromising system integrity and confidentiality. The weakness is classified as CWE‑416 (Use After Free).
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1 (ARM64 and x64 architectures) as well as the Windows Server operating systems provide the native NAT helper component that contains the flaw.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. An attacker must already have local or authorized privileges to trigger the use‑after‑free condition; precise timing within ipnathlp.dll is required. Despite the low exploitation likelihood, the severity warrants prompt mitigation.
OpenCVE Enrichment