Impact
From the description, a missing release of memory after its effective lifetime in the Windows DHCP Client allows an attacker to cause a denial of service on the host connected to an adjacent network. The flaw does not provide a path for code execution or data exfiltration; instead, it simply interrupts the DHCP client’s operation, potentially preventing the host from obtaining or renewing IP addresses and thereby disabling network connectivity. The vulnerability is mapped to CWE-401, indicating a memory management issue that can lead to resource exhaustion.
Affected Systems
Affected systems are Microsoft Windows 11 in the 24H2, 25H2, and 26H1 release tracks, as well as Microsoft Windows Server 2025, including both standard and Server Core installations. The list of CPEs reflects ARM64 builds for Windows 11 24H2 and 25H2 and an x64 build for Windows 11 26H1, with servers running on standard architectures. All current releases of these operating systems are vulnerable until the patched update is applied.
Risk and Exploitability
The CVSS score of 6.5 places this flaw in the medium severity range. No EPSS score is published, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely known exploits yet. Nevertheless, an attacker who can reach the affected host from a neighboring or compromised network segment can trigger the denial of service simply by interacting with the DHCP client, which is a local-network-level threat. System administrators should monitor DHCP service status and apply the security update as soon as it becomes available to mitigate the risk.
OpenCVE Enrichment