Impact
A heap-based buffer overflow in the Windows DHCP Server component permits an authorized attacker to execute arbitrary code over a network. The flaw can be triggered by sending specially crafted DHCP messages, enabling the attacker to take control of the server process.
Affected Systems
Microsoft Windows 10, versions 1607 and 1809, and Windows Server editions from 2012 through 2025 (including Server Core installations). Users running any of these operating systems with the DHCP Server role are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The attack vector is network-based, and the description specifies that an authorized attacker is required to exploit the flaw.
OpenCVE Enrichment