Impact
The vulnerability is a heap-based buffer overflow in the Windows DHCP Server that can be triggered by authorized or adjacent network traffic. When exploited, it allows an attacker to gain higher privileges on the target system, effectively escalating local or network authority. This flaw falls under CWE-122 and can result in unauthorized system control if not mitigated.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607 and 1809, and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, across both standard and Server Core installations. Any deployment running the DHCP service from these versions is vulnerable.
Risk and Exploitability
The CVSS score of 8 categorises it as a high‑severity flaw, and the EPSS score of less than 1% indicates that active exploitation is currently rare. It is not listed in the CISA KEV catalog. The likely attack vector is local or requires an attacker with privileges on a network segment that can send crafted DHCP packets, as the description references an adjacent network implies. Attackers would need to target the DHCP service directly to trigger the overflow.
OpenCVE Enrichment