Impact
The vulnerability in the Windows DHCP Client allows an attacker to cause uncontrolled resource consumption, which can lead to a denial of service for the affected host and the adjacent network. This flaw falls under CWE‑400 and gives an unauthorized actor the ability to exhaust the client’s resources without authentication.
Affected Systems
Microsoft Windows 11 24H2, 25H2, and 26 H1, as well as Microsoft Windows Server 2025 (including Server Core installations). The affected Windows 11 releases are arm64 for 24H2 and 25H2, while 26 H1 runs on x64; the server version is affected on all architectures.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, but the EPSS score below 1 % implies that the likelihood of exploitation remains very low. The vulnerability is not listed in the CISA KEV catalog, meaning no known widespread exploitation. An attacker would need to be on the same network segment to send crafted DHCP packets that trigger the resource exhaustion; no authentication or elevated privileges are required.
OpenCVE Enrichment