Impact
The vulnerability is an integer underflow (CWE-191) that occurs in the Windows DHCP Client. When the condition is triggered, it can lead to elevation of privileges on the host. The consequence is that a user or process with insufficient rights may gain elevated local privileges, potentially leading to full system compromise, unauthorized modification of files, or installation of malicious software. Because the flaw lies in a core networking component, it can affect data confidentiality, integrity, and availability for all users on the victim machine. The exact method to trigger the flaw is not stated in the CVE description.
Affected Systems
Microsoft Windows 10 Version 1607, Microsoft Windows 10 Version 1809, Microsoft Windows Server 2012, Microsoft Windows Server 2012 (Server Core installation), Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012 R2 (Server Core installation), Microsoft Windows Server 2016, Microsoft Windows Server 2016 (Server Core installation), Microsoft Windows Server 2019, Microsoft Windows Server 2019 (Server Core installation), Microsoft Windows Server 2022, Microsoft Windows Server 2025, Microsoft Windows Server 2025 (Server Core installation).
Risk and Exploitability
The CVSS score of 7.5 indicates a high risk of compromise if abused. The EPSS score of less than 1% suggests that the likelihood of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. It is inferred that triggering the flaw may require network-based interaction, though the exact attack vector is not specified in the CVE description. Once the underflow is triggered, the attacker could gain local administrative privileges and execute arbitrary code.
OpenCVE Enrichment