Impact
The vulnerability is a stack‑based buffer overflow in the Windows DHCP Server component that allows an attacker with authorized network access to inject and execute arbitrary code on the server. This means an attacker could gain full control of the DHCP service, potentially impacting all clients that rely on it for IP configuration. The flaw exposes the server to remote code execution over the adjacent network.
Affected Systems
Affected systems are Microsoft Windows 10 versions 1607 and 1809 on desktop machines. On the server side, the vulnerability covers all supported Windows Server releases from 2012 (both standard and core installations) through 2025, including 2012 R2, 2016, 2019, 2022 and 2025 editions. No other product variants are listed.
Risk and Exploitability
The CVSS score of 8.0 marks this as a high‑severity problem. EPSS information is not available, so the exact exploitation probability is unknown, but the nature of the flaw—a stack buffer overflow that can lead to arbitrary code execution—suggests that a skilled attacker with network access could succeed. Microsoft has not listed this issue in its KEV catalog, yet the potential impact of compromising a DHCP server is significant. Organizations should treat this as a priority when assessing risk.
OpenCVE Enrichment