Impact
The CVE notes an out‑of‑bounds read in the Windows DHCP Server. The primary impact is that the DHCP service crashes, causing a denial of service to clients. This conclusion is inferred from the description stating the service terminates; the CVE does not explicitly describe the attacker’s input or crash mechanism.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809 and Windows Server releases from 2012 to 2025, including Server Core installations, are affected. The vulnerability resides in the DHCP server component.
Risk and Exploitability
The flaw has a CVSS score of 7.5, classified as high severity. The EPSS score is reported as less than 1%, indicating exploitation is considered rare, but the CVE does not specify the exact conditions. It is inferred that an unauthenticated attacker on the same network could trigger the exploit, as the DHCP protocol is broadcast-based. The vulnerability is not listed in CISA KEV, so it is not known to be actively exploited in the wild. Monitoring for unexpected DHCP resets could help detect attacks, though the CVE does not provide evidence that such monitoring is effective.
OpenCVE Enrichment