Impact
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. This flaw is classified as CWE-125.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including the corresponding Server Core installations.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and the EPSS score of < 1 % suggests limited publicly known exploitation. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must have access to the machine running the DHCP client. No remote exploitation capability is documented.
OpenCVE Enrichment