CVE-2026-58537: Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability
Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability
Other sources
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2525Patch KB5101649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8875Patch KB5101650
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized on the affected system and able to execute an attack locally. The provided information does not indicate that remote exploitation or user interaction is required.
Which systems are identified as affected?
The listed affected software includes Microsoft Windows 11, Microsoft Windows Server 2025, Windows 11 24H2, Windows 11 25H2, and Windows 11 26H1.
What is the likely impact of successful exploitation?
Successful exploitation allows local elevation of privilege. The supplied severity vector indicates high impacts to confidentiality, integrity, and availability.