Impact
The vulnerability is a use‑after‑free flaw in the Windows DHCP Client that permits an unauthorized attacker to execute arbitrary code on the affected system. The weakness is a classic use‑after‑free bug (CWE‑416) and the impact is the ability to run malicious code locally, potentially compromising system confidentiality, integrity, and availability.
Affected Systems
Affected Microsoft Windows products include Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 24H2, 25H2, and 26H1; and various Windows Server editions from 2012 through 2025, including Core installations. The affected platforms span x86, x64, and arm64 architectures as reflected in the supplied CPE strings.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity risk. The EPSS score of less than 1% implies a low likelihood of active exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an attacker who can trigger the DHCP Client code paths from the target machine or from local user interactions. No external network entry or elevation of privilege is described in the available data.
OpenCVE Enrichment