Impact
This vulnerability arises from a type confusion in the Windows DHCP Server’s handling of resource access, resulting in a denial of service. An attacker can trigger this flaw by sending specially crafted DHCP traffic, causing the server to crash or become unresponsive. The impact is a loss of availability for network clients relying on DHCP, with no direct confidentiality or integrity compromise noted.
Affected Systems
Microsoft Windows 10 Version 1607 and 1809, Microsoft Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, including their Server Core installations. These releases are listed in the CNA affected product list, and all supported variants of these operating systems are impacted.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity for this remote, network-based attack. The EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating that it may not yet be widely exploited. The likely attack vector is an unauthenticated network attacker sending malformed DHCP packets. Successful exploitation requires no local privileges and leads to service denial on the affected DHCP Server.
OpenCVE Enrichment