Impact
An out‑of‑bounds read occurs in the Windows DHCP Server when it processes a specially crafted request. The flaw can be triggered by an unauthorized attacker on the network, forcing the DHCP service to crash and become unavailable, which prevents clients from obtaining IP addresses and disrupts network communications.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, and Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022 and 2025, including their Server Core editions.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating high severity. No authentication is required, and the attack is conducted remotely from the network over the DHCP service. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, but its high CVSS and remote nature make exploitation likely against exposed servers.
OpenCVE Enrichment