Impact
A memory management flaw in Windows DHCP Server releases previously allocated memory too late, allowing an authorized attacker to generate traffic that causes the server to consume resources and eventually become unavailable, thereby denying service to legitimate clients.
Affected Systems
Affected systems include Microsoft Windows 10 Version 1607 and 1809, Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk. The EPSS score is 1%, and the vulnerability is not listed in CISA KEV. Exploitation requires an authorized attacker with sufficient privileges to send crafted packets to the DHCP service, resulting in resource exhaustion and service disruption.
OpenCVE Enrichment