Impact
The vulnerability is a heap-based buffer overflow in Windows DHCP Server. This flaw permits an attacker who can send crafted DHCP packets from an adjacent network to overwrite memory and execute arbitrary code with the privileges of the DHCP service. The primary impact is remote code execution, caused by an unchecked buffer handling error (CWE-122).
Affected Systems
Affected Windows operating systems include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both standard and Server Core installations). All build packages containing the Windows DHCP Server component are impacted.
Risk and Exploitability
The CVSS score is 8, indicating a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authorized attacker within the same network segment or VLAN to send malicious DHCP packets. While no publicly disclosed exploitation packages are currently known, the remote code execution potential and adjacency requirement mean that an attacker could compromise the DHCP server to achieve system-wide compromise if the target network is not properly segmented or protected.
OpenCVE Enrichment