Impact
The vulnerability is an out-of-bounds read in the Windows DHCP Client that enables an unauthorized local attacker to read sensitive data from memory, exposing private information. This flaw is classified under CWE-125 (memory read out-of-bounds) and results in a local information disclosure.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and the EPSS score of < 1 % suggests limited publicly known exploitation. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must have access to the machine running the DHCP client. No remote exploitation capability is documented.
OpenCVE Enrichment