Impact
Windows DHCP Server is vulnerable to uncontrolled resource consumption, enabling an unauthorized attacker to cause a denial of service over the network. The flaw lies in the server’s failure to limit processing of certain DHCP packets, which can exhaust CPU or memory and render the service unresponsive. This compromises availability and can interrupt IP address allocation for legitimate clients, but does not involve data compromise or privilege escalation.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607 and 1809 and all Windows Server releases from 2012 through 2025, including Server Core installations. All these operating systems run the native DHCP Server service in the OS, making them susceptible to exploitation.
Risk and Exploitability
With a CVSS score of 7.5, the severity is moderate to high for availability. The EPSS score of < 1% indicates that exploitation is considered unlikely at present, and the vulnerability is not listed in CISA KEV. According to the description, an attacker can send specially crafted DHCP packets over the network without authentication, implying a likely outsider with network-level access. Successful exploitation would cause the DHCP Server to become unresponsive and deny service to legitimate clients, but neither data nor higher privileges are exposed.
OpenCVE Enrichment