Vulnerability record · CVE-2006-5614 · published 31 October 2006
CVE-2006-5614: Windows NAT Helper null pointer dereference via malformed DNS query
Microsoft · Windows Nt Helper Components
The Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, mishandles a malformed DNS query and dereferences a null pointer. This crashes the hosting svchost.exe process, causing a denial of service. The flaw only matters on hosts where ICS is actually enabled.
Description
Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference.
AV:N/AC:H/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is only a denial of service and requires ICS to be enabled plus high access complexity, but public exploit code and a very high EPSS score raise the practical risk.
What it is
The Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, mishandles a malformed DNS query and dereferences a null pointer. This crashes the hosting svchost.exe process, causing a denial of service. The flaw only matters on hosts where ICS is actually enabled.
Impact
A remote attacker can crash the svchost.exe process hosting the NAT Helper, disrupting Internet Connection Sharing and any dependent network services on the affected host. There is no confidentiality or integrity impact; the effect is availability loss.
Attack surface
Reachable over the network (AV:N) by sending a malformed DNS query to a host running ICS; no authentication is required (Au:N). The CVSS vector rates access complexity as high (AC:H), and no user interaction is described.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.79213, 99.579th percentile) and a public Exploit-DB entry (2672) exists, indicating exploit code is publicly available.
What to do
- Apply the Microsoft update for the Windows NAT Helper Components on affected Windows XP SP2 systems.
- Disable Internet Connection Sharing on hosts that do not require it, which removes the vulnerable code path.
- Block or filter inbound DNS traffic to ICS-enabled hosts at the network perimeter where feasible.
- Upgrade or retire Windows XP SP2 systems, which are long past end of support.
Detection
- Monitor for svchost.exe crashes and unexpected restarts on ICS-enabled Windows XP hosts.
- Alert on Windows Error Reporting or event log entries referencing ipnathlp.dll faults.
- Watch for anomalous or malformed DNS query patterns directed at ICS-enabled hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5614 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5614), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.