Impact
A double free flaw in the Windows DHCP Server program enables an attacker who has authorized access to the network to execute arbitrary code. The vulnerability stems from a memory management error that can be triggered by sending specially crafted DHCP packets. Because the flaw allows code to run with the same privileges as the DHCP service, a successful exploit can compromise the entire system to the level of that service, potentially leaking confidential data, executing malware, or establishing persistence.
Affected Systems
Affected products include Microsoft Windows 10, versions 1607 and 1809, and Windows Server releases from 2012 through 2025, both on standard and core installations. The vulnerability applies to the DHCP Server component in these operating systems.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is less than 1%, suggesting that while the probability of exploitation is low, the vulnerability remains serious. The vulnerability is not listed in CISA’s KEV catalog. An authorized network attacker can send crafted DHCP packets to the server to trigger the double free. Because the flaw requires networking access and the attacker’s packets to be processed by the DHCP service, the attack vector is network-based with the attacker needing legitimate presence on the same local network or VPN.
OpenCVE Enrichment