Impact
A missing authentication check allows an attacker with local rights to modify the configuration of Windows Internet Connection Sharing. The flaw does not grant remote exploitation or privilege escalation; it only permits local tampering of how shared connections are presented or used. Consequently, a user who can run code on the machine could change network sharing settings, potentially redirect traffic or disrupt network connectivity without requiring elevated privileges.
Affected Systems
Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server releases 2016, 2019, 2022, 2025—including both full and server‑core installations are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.5. EPSS data is not available in the CVE record, so the current exploitation probability cannot be determined. It is not listed in the CISA KEV catalog, indicating no widespread exploitation has been reported. An attacker only needs local access; no external network vector is required. The lack of authentication for the critical IPC service corresponds to CWE‑306, restricting the attack surface to local users who can interact with the Windows Internet Connection Sharing service.
OpenCVE Enrichment