Impact
A use‑after‑free condition exists in the Windows DHCP Server that permits an attacker to trigger code execution on the host that is running the DHCP service. The vulnerability is categorized under CWE‑416 and could be exploited to run arbitrary code with the privileges of the DHCP service. The potential impact includes full system compromise, data theft, and further lateral movement within the network.
Affected Systems
Affected Microsoft products include Windows 10 (versions 1607 and 1809) and the Windows Server family from 2012 through 2025, covering both full and Server‑Core installations. The DHCP Server component in each of these operating systems is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, reducing the public knowledge of targeted exploitation. The attack vector is inferred to involve network traffic, as the DHCP service listens for requests on the local network. An attacker in proximity to the DHCP server could send crafted packets that trigger the use‑after‑free fault and gain code execution on the host.
OpenCVE Enrichment