Impact
A stack-based buffer overflow in the Windows DHCP Client can allow an attacker with local authorization to execute arbitrary code with elevated privileges. The flaw enables the attacker to raise their permissions to system level, compromising confidentiality, integrity, and availability on the affected computer.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012 (including Server Core), 2012 R2 (including Server Core), 2016, 2019, 2022, and 2025 (including Server Core). All listed builds contain the vulnerability.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation. The EPSS score is <1%, meaning exploitation probability is very low but nonzero. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires local access and interaction with the DHCP Client, likely through crafted DHCP packets or a local exploit of the stack overflow. The likely attack vector is local network traffic from a compromised machine; no remote trigger is documented. Once exploited, the attacker can gain system‑level privileges, affecting all aspects of the affected host.
OpenCVE Enrichment