Impact
This vulnerability is an out‑of‑bounds read in the Windows DHCP Server, which can be exploited by an authorized attacker to cause a denial of service. The flaw is a classic example of improper bounds checking (CWE‑125) combined with an incorrect type conversion (CWE‑843), leading to memory corruption that disrupts DHCP operation. An attacker who can trigger the read will be able to prevent the server from allocating or responding to DHCP requests, effectively taking the network’s IP address allocation out of service.
Affected Systems
Microsoft Windows 10 version 1607 and 1809, as well as Windows Server 2012 through 2025 (including core installations). These systems include the built‑in DHCP Server component. No specific sub‑versions are listed beyond the major releases, but all builds in the affected product families are potentially vulnerable.
Risk and Exploitability
The CVSS score for this issue is 5.7, indicating moderate severity. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector requires an attacker with authorized or privileged access to the network or the target system; malicious attempts would typically target the DHCP service running on the same local subnet to disrupt IP allocation for users or connected devices.
OpenCVE Enrichment