Impact
The vulnerability is a stack‑based buffer overflow in the Windows DHCP Server that allows an attacker lacking local privileges to deliver malicious input to the DHCP service and execute arbitrary code. This flaw can compromise the confidentiality, integrity, and availability of the affected system by running attacker‑controlled code with system privileges, potentially enabling full system takeover.
Affected Systems
Affected vendors and products include Microsoft Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, including the server core installations. The vulnerability applies to all listed versions as confirmed by the CNA and is represented in the provided CPE strings.
Risk and Exploitability
With a CVSS score of 8.1, the vulnerability is considered high severity. The EPSS score is not available, but the lack of a KEV listing suggests no public exploit is reported yet; however, the nature of the flaw being a buffer overflow and the fact that it can be triggered over the network make it potentially exploitable by a remote attacker with no authentication. The likely attack vector is the network, requiring an attacker to send crafted DHCP packets to the vulnerable server from a remote host.
OpenCVE Enrichment