Impact
The Windows DHCP Server contains an integer underflow flaw that allows an unauthorized network actor to read data from memory adjacent to the variable that holds DHCP packet fields. Because the underflow causes a wraparound, the server may return incorrectly calculated values that expose sensitive configuration information. The flaw maps to CWE‑125 (Out‑of‑Bounds Read) and CWE‑191 (Integer Underflow). Successful exploitation results in the disclosure of confidential configuration details, but does not grant code execution or privilege escalation.
Affected Systems
Affected are Microsoft Windows 10 build 1607 and 1809, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022 and the new 2025 releases. Both standard and Server Core installations are impacted. The vulnerability continues to exist in all or sub‑versions of these operating systems; the advisory includes all versions in its impact statement.
Risk and Exploitability
Denoted with a CVSS score of 6.5, the flaw is considered moderate severity, and the EPSS score of less than 1 % indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker requires network proximity to a DHCP server – for example, a device connected to the same local network or a compromised router that relays DHCP traffic – and can send crafted DHCP packets to trigger the underflow. No elevated privileges are required on the host, but the attacker must be able to observe the DHCP server’s response to glean the leaked information.
OpenCVE Enrichment