Impact
An out‑of‑bounds read bug exists in the Windows DHCP Server, allowing an attacker with legitimate privileges to send crafted DHCP packets that trigger a memory read beyond allocated bounds. This flaw enables the attacker to cause a service failure on the server, resulting in denial of service for clients on the adjacent network. The vulnerability falls under common weaknesses that involve improper bounds checking and type confusion.
Affected Systems
Microsoft Windows 10 releases 1607 and 1809, Windows Server 2012 and 2012 R2, Windows Server 2016, 2019, 2022, and the upcoming 2025, in both full and Server Core editions, are affected. The flaw is present in all editions that contain the default DHCP server component.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate impact. No EPSS score is available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, suggesting it is not widely targeted at present. Exploitation requires an attacker to have authorized access to the DHCP server or the ability to submit malicious DHCP traffic from an adjacent network. Once triggered, the server ceases to respond to client requests, disrupting network services for users in that subnet.
OpenCVE Enrichment