Impact
A use‑after‑free flaw in Windows IP Helper allows an unauthorized attacker to execute code on a networked system. The vulnerability’s primary impact is Remote Code Execution, giving an attacker control over the affected host and potentially compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects a wide range of Windows operating systems, including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server editions from 2012 through 2025, encompassing both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. While an EPSS score is not publicly available, the lack of a KEV listing does not reduce the risk; the high CVSS combined with the remote-attack nature suggests that exploitation is feasible over a network. The attacker would need to send specially crafted network traffic targeting IP Helper; successful exploitation would allow arbitrary code execution with the privileges of the compromised service.
OpenCVE Enrichment