Impact
An out-of-bounds read in the Windows DHCP Server allows an authorized attacker to trigger a memory read beyond valid boundaries that enables the execution of arbitrary code on the host with local privileges. The vulnerability does not contain a denial-of-service component based on the available description; it focuses solely on code execution possibilities.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, Windows Server 2012 (both standard and Server Core installations), Windows Server 2012 R2 (both standard and Server Core installations), Windows Server 2016, Windows Server 2019 (both standard and Server Core installations), Windows Server 2022, and Windows Server 2025 (both standard and Server Core installations).
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity level. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The vulnerable code is reachable only by an authorized attacker with network access to the DHCP service, implying proximity to the target. While the risk is moderate, the impact of any successful exploitation is significant and therefore mitigation should be performed promptly.
OpenCVE Enrichment