ZeroHour

CVE-2026-72981

mass

Use-After-Free RCE in Microsoft Windows IP Helper Service

CVSS 3.1
8.1 high
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2026-72981 is a use-after-free memory corruption flaw (CWE-416) in the IP Helper service of Microsoft Windows, assigned by Microsoft and addressed in the September 2026 security updates. An unauthenticated remote attacker can trigger the condition by getting the service to process malicious network input, though the high attack-complexity metric (AC:H) means reliable exploitation likely depends on specific memory layout or timing conditions. Successful exploitation grants the attacker arbitrary code execution on the target host with the privileges of the IP Helper service. Any Windows system running the IP Helper service, which is enabled by default on typical Windows installations, is potentially affected, although the disclosure does not specify exact affected version ranges. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists; EPSS currently estimates only a 0.5% probability of exploitation within 30 days.

What to do: Apply Microsoft's September 2026 security updates (the relevant cumulative update for each Windows build) across endpoints and servers, prioritizing internet-exposed Windows hosts. Because the disclosure does not list exact affected versions, verify against Microsoft's advisory which builds require the fix before scheduling. Until patched, favor standard patch-cycle prioritization given the high attack complexity and lack of known exploitation, and review systems where the IP Helper service processes untrusted network traffic.

Affected
Microsoft Windows (IP Helper service)
Estimated exposure
masshundreds of millions of Windows installations (IP Helper runs by default on Windows deployments) — Windows holds the dominant share of enterprise and consumer desktop/server installs and the IP Helper service ships and runs by default, so the potential population is on the order of the overall Windows install base, though the exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in IP Helper allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.