Impact
The vulnerability is an out‑of‑bounds read in Windows DHCP Server that allows an unauthorized attacker to crash the service, denying DHCP functionality to clients. The flaw is a classic array bounds problem (CWE‑125) and results solely in a denial of service; it does not provide code execution or data disclosure.
Affected Systems
Microsoft Windows 10 16‑07, Microsoft Windows 10 18‑09, Microsoft Windows Server 2012, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Windows Server 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact on availability. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known public exploitation yet. Based on the description, the likely attack vector is via the network: an attacker sends a specially crafted DHCP request to the server, causing the out‑of‑bounds read that leads to a service crash. Because the DHCP service is critical for network operation, an unpatched system is at significant risk of experiencing downtime from an unauthorized network actor.
OpenCVE Enrichment