Impact
The vulnerability in Windows DHCP Server arises from a type confusion condition that allows an attacker to access a resource with an incompatible type. This flaw can cause the DHCP service to crash or become unresponsive, resulting in a denial of service that impacts clients on the affected network. The error is triggered by an unauthorized attacker sending a crafted DHCP request, leading to a disruption of the DHCP service without the need for local user privileges.
Affected Systems
Affected releases include Microsoft Windows 10 from version 1607 onward, Microsoft Windows Server 2012 through 2025, and their Server Core variants. The vulnerability is present across all listed Windows Server editions and the listed Windows 10 updates that ship the DHCP Server role.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the lack of an EPSS value suggests limited publicly known exploitation data; however, because the flaw is network‑bound and does not require local authentication, a remote attacker could exploit it by simply sending a malformed DHCP packet. The vulnerability is not listed in the CISA KEV catalog, implying no current widespread exploitation, but the potential for service disruption remains significant for networks relying on the DHCP service.
OpenCVE Enrichment