Impact
An out‑of‑bounds read vulnerability has been identified in the Windows DHCP Server. This flaw permits an attacker with local authorization to read sensitive data from memory that should not be accessible, potentially exposing confidential system information. The weakness is categorized as CWE‑125.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including the corresponding Server Core installations.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and the EPSS score is not available, suggesting limited publicly known exploitation. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must have authorization to the machine hosting the DHCP service or to the network segment that allows interaction with the DHCP server. No remote exploitation capability is documented.
OpenCVE Enrichment