Impact
A heap-based buffer overflow in the Windows DHCP Server allows an unauthorized attacker to execute code over a network. The flaw can lead to arbitrary code execution within the DHCP server process, potentially compromising the DHCP service and affecting the broader network.
Affected Systems
Affected Windows operating systems include Windows 10 (Version 1607 and Version 1809) and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, all in both standard and Server Core configurations.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of 11 % suggests a significant likelihood of exploitation. The official description indicates that the heap-based overflow can be triggered in the DHCP service, so an attacker may exploit the flaw from the network. This inference is drawn from the wording and is not explicitly detailed in the advisory. The vulnerability is not listed in the CISA KEV catalog, but its high severity and exploitation probability make it a high‑priority risk for environments running a DHCP server.
OpenCVE Enrichment