Impact
Windows DHCP Server contains an integer overflow or wraparound flaw that permits an attacker who can send specially crafted DHCP packets to the server to execute arbitrary code. The overflow occurs during packet parsing, enabling control over the execution flow once the server processes the malformed request. This leads to remote code execution, potentially compromising the host, allowing an attacker to gain full control of the affected system and to pivot to other network resources. The flaw affects integrity and confidentiality and can be used to disrupt network services.
Affected Systems
Microsoft Windows 10 version 1607 and 1809, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations), are susceptible. The affected builds include both client and server variants where the DHCP Server role is installed. All affected systems are listed in the Microsoft advisory referenced above.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered high severity. The EPSS score is currently not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known publicly exploited instances at the time of this analysis. The exploit requires network-level access to send malicious DHCP packets to the target, suggesting that attackers must be on the same broadcast domain or have the ability to tunnel traffic to the server. Given the lack of known exploitation and the high CVSS, the risk remains significant but may be mitigated by network segmentation or firewall controls until a patch is applied.
OpenCVE Enrichment