Impact
This vulnerability is a heap‑based buffer overflow in the Windows DHCP Client. By delivering specially crafted data to the client, an attacker who is already authorized on the local machine can cause the overflow and elevate privileges, potentially achieving full system control. The weakness corresponds to CWE‑122, a lack of bounds checking leading to unchecked memory writes. The exploit could compromise the confidentiality, integrity, or availability of the affected system, depending on the attacker’s objectives. The description does not provide details on any network‑level or remote execution capability, so the impact is confined to local privilege escalation.
Affected Systems
Microsoft Windows 11 versions 23 H2, 24 H2, 25 H2 and 26 H1, as well as Windows Server 2025 (including Server Core installations) are affected. The vulnerability applies to both ARM64 and x64 architectures for the listed Windows 11 releases and to all architectures reported for Windows Server 2025.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk. The EPSS score is not available, but the lack of a current KEV listing suggests the vulnerability has not yet been widely exploited in the wild. The likely attack vector requires an attacker to be authorized locally; thus, the opportunity is an insider or someone who has gained initial access to the machine. Given the severity score and the local elevation nature of the flaw, the risk to impacted systems is significant, especially in environments where privileged users can execute code on the machine. Implementing the official patch as soon as possible is essential to mitigate this risk.
OpenCVE Enrichment