Impact
The flaw exists in the Windows DHCP Server and permits an attacker who is not authenticated to tamper with DHCP traffic over the network. An attacker can send crafted DHCP packets that alter the behavior of the DHCP service, potentially changing how the server assigns addresses or other configuration data. The vulnerability does not grant code execution or broader system control directly, but it enables manipulation of network configuration.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, and their server‑core editions. All listed releases run the vulnerable DHCP Server component.
Risk and Exploitability
The CVSS score is 9.1, indicating critical severity. No EPSS information is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is a remote network attacker who can reach the DHCP service and send malicious DHCP packets. No authentication or special privileges are required, making exploitation possible from any device on the same network segment.
OpenCVE Enrichment