Impact
An out‑of‑bounds read bug in the Windows DHCP Server enables an attacker who can send crafted DHCP traffic from within the same local network to read memory contents that are not intended for disclosure, thereby leaking sensitive information across the network and compromising confidentiality.
Affected Systems
Microsoft Windows 10 Releases 1607 and 1809, and Windows Server 2012 through 2025 – including all full installations and Server Core variants – are impacted by the vulnerability in their built‑in DHCP Server component.
Risk and Exploitability
The base CVSS score of 5.9 rates the issue as medium severity, and the absence of an EPSS score together with its current non‑listing in CISA’s KEV catalog suggests that widespread exploitation has not yet been observed. The attack requires the adversary to communicate with the DHCP service over the local network, meaning the risk is confined to environments where the DHCP server is reachable to potential attackers and where the server is not isolated behind restrictive controls.
OpenCVE Enrichment