Impact
A bug in the Windows DHCP Server causes an out‑of‑bounds read when a DHCP request arrives, allowing an attacker who can send or observe DHCP traffic to access sensitive data from the server’s memory. This flaw permits disclosure of internal information over the network without authentication or privilege escalation. The underlying weakness is a buffer underrun (CWE‑125).
Affected Systems
Microsoft Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, Server 2025 – both standard and Server Core editions are affected.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity risk. No EPSS score is provided, so the probability of exploitation is unknown, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network‑based; an unauthenticated attacker who can send crafted DHCP packets to the server can trigger the out‑of‑bounds read and capture disclosed data. No specialized prerequisites beyond network access to the DHCP service are mentioned in the description.
OpenCVE Enrichment