Impact
A heap‑based buffer overflow exists in the Windows DHCP Client that allows an authorized attacker to gain elevated privileges on an adjacent network. The flaw resides in the handling of DHCP messages and can be leveraged to execute arbitrary code with higher privileges, potentially allowing modification of system settings or compromise of other networked devices. The weakness is classified by CWE‑122, indicating classic heap corruption.
Affected Systems
The vulnerability affects Microsoft Windows 11 versions 24H2, 25H2, and 26H1. The earlier builds (24H2 and 25H2) are identified for ARM64 architectures, while 26H1 applies to x64 systems. Only these releases are known to be impacted.
Risk and Exploitability
With a CVSS score of 8, the vulnerability is considered high severity. The EPSS score is not available, and the issue is not currently listed in the CISA KEV catalog, suggesting limited documented exploitation at this time. Based on the description, it is inferred that the attack vector is a network‑based scenario, where an attacker with legitimate network access crafts malicious DHCP packets to trigger the overflow and elevate privileges on the target host or adjacent devices. Because the flaw requires an authorized attacker who can influence DHCP traffic, the attack surface is restricted but still significant for environments with unmanaged or poorly monitored network infrastructure.
OpenCVE Enrichment