Impact
A type‑confusion flaw in the Windows DHCP Server allows an unauthorized network participant to cause the service to crash, disrupting address allocation for client devices. The vulnerability arises from accessing a resource with an incompatible type, leading to an uncontrolled exception that terminates the DHCP process. This denial of service can affect the availability of IP address assignment to all devices relying on the affected server.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809 and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations) are listed as impacted. These operating systems host the DHCP service that may be exposed on internal or boundary networks.
Risk and Exploitability
The flaw has a CVSS score of 7.5, indicating substantial severity. The EPSS score is not available, so the current exploitation probability is unclear, and the vulnerability is not listed in the CISA KEV catalogue, suggesting no confirmed widespread attacks yet. The attack vector is likely network‑based, with an attacker able to send crafted requests to the DHCP server to trigger the crash. An internal or compromised host on the same network could exploit this weakness; external exploitation would require initial network access or exploitation of a separate vulnerability to reach the DHCP service.
OpenCVE Enrichment