Impact
The vulnerability is an integer underflow in the Windows DHCP Server that can leak memory content to an unauthorized attacker. The flaw allows the attacker to read data located outside the intended bounds of a buffer, potentially exposing sensitive information such as configuration details or network secrets. The weakness is associated with CWE-125 and CWE-191.
Affected Systems
Affected systems include Microsoft Windows 10 version 1607, Windows 10 version 1809, and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, along with their corresponding Core installations. Both 32‑bit and 64‑bit editions are listed as impacted by this issue.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests the likelihood of exploitation is low at this time. The vulnerability is not catalogued in the CISA KEV list. Based on the description, the likely attack vector is a network adjacent attacker exploiting the DHCP service exposed on the local network. The flaw permits information disclosure only to an attacker who can reach the DHCP server’s network interface, therefore the exploitation requires local or near‑network access. Overall, while the impact is limited to disclosure of data, the probability of active exploitation remains low.
OpenCVE Enrichment