Impact
A stack-based buffer overflow exists in the Windows DHCP Server that lets an attacker who is not authenticated execute arbitrary code over the network. The flaw can be triggered by sending specially crafted DHCP packets, providing the attacker with the ability to compromise the server process with high privileges, potentially enabling full control over the affected system. This weakness is classified as CWE-121, indicating a classic stack overflow scenario that can overwrite return addresses or other critical data structures.
Affected Systems
Affected builds include Microsoft Windows 10 Version 1607 and Version 1809, as well as all current and legacy Windows Server releases that ship a DHCP Server component: Windows Server 2012, 2012 R2, 2016, 2019, 2022, and the upcoming Windows Server 2025, across both full installations and Server Core configurations. All versions in the supplied list are impacted.
Risk and Exploitability
The CVSS score of 8.1 reflects a high severity remote code execution risk that does not require local privilege. The EPSS score is not available, so no current data indicates how frequently this has been exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, but the nature of the flaw—a stack buffer overflow in a network-facing daemon—makes it a likely candidate for exploitation by attackers with network access. The attack vector is inferred to be network, as the DHCP Server processes inbound DHCP messages.
OpenCVE Enrichment