Impact
A heap‑based buffer overflow in the Windows DHCP Server allows an unauthorized actor to run arbitrary code on the host when the server processes specially crafted packets. The flaw resides in input handling, enabling the attacker to manipulate server memory. Successful exploitation could compromise confidentiality, integrity, and availability of the affected machine, effectively giving the attacker full control over the system.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607 and 1809 and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both normal and Server Core installations. All variants are impacted, regardless of CPU architecture (x86 or x64).
Risk and Exploitability
With a CVSS score of 9.8 the flaw is considered critical. The EPSS score is not available, but the lack of KEV listing does not reduce its threat. The likely attack vector is network‑based, requiring an attacker to send crafted DHCP traffic to the vulnerable server. No special privileges or host access are required; the attack can be carried out remotely from an external or internal network segment that can reach the DHCP service.
OpenCVE Enrichment