Junglewise Threat Intelligence

CVE-2026-72981: Microsoft Windows IP Helper use-after-free remote code execution

CVE-2026-72981 · Severity: high · CVSS 8.1 · Published 2026-09-08

Executive brief

Microsoft Windows IP Helper is a core networking service that manages TCP/IP protocol operations on Windows systems. A use-after-free vulnerability in this service allows an attacker to execute arbitrary code remotely on vulnerable systems, potentially compromising network infrastructure and sensitive business operations without requiring prior authentication.

Technical details

A use-after-free vulnerability exists in the Windows IP Helper service, a critical networking component that handles TCP/IP protocol management. The vulnerability allows an unauthenticated attacker to trigger memory corruption by sending specially crafted network packets, leading to remote code execution with the privileges of the IP Helper service. The attack vector is network-based and does not require user interaction or prior authentication. An attacker can exploit this to execute arbitrary code and potentially gain elevated privileges on the target system.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats