Impact
The vulnerability is an out‑of‑bounds read in the Windows DHCP Server stack that allows an unauthenticated attacker to read memory contents over the network. This results in an information disclosure that can compromise the confidentiality of sensitive data such as configuration parameters, user credentials, or internal network information. The weakness is described by CWE‑125.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607 and 1809 as well as Windows Server 2012 through 2025 (both full and Server Core installations). The vulnerability applies to both 32‑bit and 64‑bit builds as indicated by the listed CPEs.
Risk and Exploitability
The CVSS score of 5.9 labels the flaw as moderate, and it is not currently listed in the CISA KEV catalog. No EPSS score is available, so the current exploitation probability cannot be quantified. The description indicates that an unauthorized attacker can exploit the flaw via network traffic to the DHCP service, implying no privileged credentials are required. Because this is an information‑disclosure flaw that can be triggered anonymously, environments that host the DHCP service should treat the risk as moderate until a patch is applied.
OpenCVE Enrichment