Impact
This vulnerability is a heap-based buffer overflow—CWE‑122—in the Windows DHCP Server. A flaw in the way the server processes DHCP packets allows an unauthorized attacker to trigger a memory corruption that can lead to arbitrary code execution. The description indicates that the attacker can execute code on the server from an adjacent network, implying that malicious DHCP traffic is the likely exploitation method.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025—including both standard and Server Core installations—are affected. All listed editions run the vulnerable DHCP Server component.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. The vulnerability is not listed in the CISA KEV catalog, but the ability to execute code remotely on a DHCP Server means an attacker could hijack network traffic, distribute malware, or elevate privileges if the server runs elevated. The inferred attack vector involves sending crafted DHCP offers from an untrusted or malicious network adjacent to the target. Acting now is prudent, as the damage potential is large and the deployment of a patch mitigates the risk entirely.
OpenCVE Enrichment