Impact
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute arbitrary code locally. The flaw arises from insufficient bounds checking when allocating memory for DHCP packets, leading to memory corruption (CWE-122). This can elevate the attacker’s privileges to match or exceed local user credentials, potentially compromising the entire system.
Affected Systems
Affected systems are Microsoft Windows 10 versions 1607 and 1809 as well as Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations. Any environment running these operating systems with the DHCP Server role enabled is vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate impact. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an authorized local attacker; remote exploitation is not supported by the current description. Because the flaw permits execution of code on the host, the risk to confidentiality, integrity, and availability is significant for systems with the DHCP Server role enabled.
OpenCVE Enrichment