Impact
A heap‑based buffer overflow within Windows DHCP Server enables an authenticated network attacker to run arbitrary code on the host. Classified as CWE‑122, the flaw stems from missing bounds checking in heap operations, permitting malicious packets to corrupt memory. The resulting full remote code execution can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Windows 10 from version 1607 onward and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including full and Server Core installations, are affected. DHCP services operating on any of these platforms are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity vulnerability. The EPSS indicates an exploitation probability of less than 1%, suggesting that widespread exploitation is unlikely at present. The vulnerability is not included in the CISA KEV catalog, but due to the RCE impact, a successful exploit would grant attackers full control over the host that runs the DHCP Server. Attackers would need access to the network segment that can communicate with the DHCP Server, and must craft specially formed DHCP packets to trigger the overflow. The relatively high severity warrants immediate attention.
OpenCVE Enrichment