Impact
A memory release bug in the Windows DHCP Server causes the service to lose memory after its effective lifetime expires. The flaw allows an authorized attacker to trigger a denial of service that stops the DHCP service on the host, which in turn blocks DHCP assignments to clients on the adjacent network. The impact is a loss of network connectivity for all devices relying on that DHCP server.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607 and 1809, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, including both full and Server Core installations.
Risk and Exploitability
With a CVSS score of 5.7 the vulnerability is of moderate severity. EPSS data is not available and the issue is not listed in the KEV catalog, suggesting no widespread, active exploitation is documented. The attack requires an authorized attacker or one with privileged access to the DHCP Server, likely through local or administrative credentials. Once exploited, the attacker can cause service disruption for all DHCP clients on the affected network segment.
OpenCVE Enrichment