Impact
The vulnerability is an out‑of‑bounds read in the Windows DHCP Server that can be triggered by an attacker who sends specially crafted DHCP messages. The flaw causes the server to access memory beyond the bounds of a buffer, causing the DHCP service to crash and terminate. Once the service stops, legitimate clients on the network cannot obtain IP addresses, resulting in a denial of service that affects network availability for all clients that rely on the DHCP server.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1607 and 1809, and all current iterations of Windows Server from 2012 through 2025, including both standard and Server‑Core installations. No further sub‑versions or build numbers were specified beyond the listed releases.
Risk and Exploitability
With a CVSS score of 7.5, the flaw is considered high severity. An explicit EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating no current widespread exploitation. The attack vector is inferred to be remote, where an unauthenticated attacker can send crafted DHCP packets that trigger the out‑of‑bounds read. Because the flaw does not require elevated privileges or authentication, any host capable of sending DHCP traffic can potentially exploit it, resulting in immediate loss of service for network clients that rely on the compromised DHCP server.
OpenCVE Enrichment