Impact
The vulnerability is a memory‑leak in the Windows DHCP Server. An unauthorized attacker can send traffic that exits the server’s effective lifetime without releasing allocated memory, causing the process to consume resources until it becomes unresponsive. This results in a denial of service to legitimate DHCP clients on the network, affecting their ability to obtain IP addresses and maintain connectivity.
Affected Systems
Microsoft Windows 10 Version 1607 and 1809, Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, including all Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of 1% indicates a low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit the issue by sending specially crafted DHCP packets across the network to trigger the memory‑leak, which would cause the DHCP service to become unresponsive and deny service to all clients on the affected subnet.
OpenCVE Enrichment