Impact
The vulnerability is an out‑of‑bounds read in the Windows DHCP Server. An unauthorized attacker can send specially crafted DHCP packets that trigger this read, causing the DHCP service to crash and denying service to clients on the network. The weakness is categorized as CWE‑125. The crash disrupts network connectivity for any hosts that rely on DHCP for IP configuration.
Affected Systems
Microsoft Windows 10 Version 1607 and 1809, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, including their Server Core installations. These systems run the vulnerable DHCP Server component that may be exposed to untrusted networks.
Risk and Exploitability
The CVSS score of 7.5 marks this as a high-severity vulnerability. The EPSS score is 1%, but the lack of KEV listing indicates no known active exploitation. The likely attack vector is remote network access, as the attacker only needs to send malicious DHCP traffic. If successfully exploited, the DHCP service will be disrupted, leading to widespread denial of service for clients in the affected network segments.
OpenCVE Enrichment