Impact
This flaw is a heap‑based buffer overflow in the Windows DHCP Server that permits an attacker who can reach the server to execute arbitrary code over the network. The weakness is identified as CWE‑122, meaning an uncontrolled memory write. An attacker who successfully exploits this vulnerability would run code with the privileges of the DHCP Service, potentially taking control of the server and jeopardising the security of the entire network segment that relies on it.
Affected Systems
Affected systems include Microsoft Windows 10 Version 1607 and 1809, Windows Server 2012 (both standard and Server Core installations), Windows Server 2012 R2 (both standard and Server Core installations), Windows Server 2016, Windows Server 2019, Windows Server 2022 and Windows Server 2025 plus their Server Core variants.
Risk and Exploitability
The CVSS base score of 9.8 notes critical severity, while the EPSS score of less than 1 % indicates the probability of exploitation is currently low but not zero. The vulnerability is not currently listed in CISA’s KEV catalog. It is inferred that an attacker must craft malicious DHCP packets and send them to the vulnerable server from an unauthenticated position on the same network. Such an attack would enable the attacker to gain code‑execution rights on the DHCP Server and potentially compromise any devices that rely on that server for IP configuration.
OpenCVE Enrichment