Impact
An unauthorized attacker can exploit a type‑confusion flaw in the Windows DHCP Server that allows access to a resource using an incompatible type. The vulnerability can be leveraged to trigger a denial of service on the DHCP service over a network, causing legitimate clients to lose network connectivity. The primary weakness is identified as CWE-843, which indicates that incorrect type handling can lead to a service interruption.
Affected Systems
Microsoft Windows 10 Version 1607; Microsoft Windows 10 Version 1809; Microsoft Windows Server 2012; Microsoft Windows Server 2012 (Server Core installation); Microsoft Windows Server 2012 R2; Microsoft Windows Server 2012 R2 (Server Core installation); Microsoft Windows Server 2016; Microsoft Windows Server 2016 (Server Core installation); Microsoft Windows Server 2019; Microsoft Windows Server 2019 (Server Core installation); Microsoft Windows Server 2022; Microsoft Windows Server 2025; Microsoft Windows Server 2025 (Server Core installation).
Risk and Exploitability
The CVSS score of 7.5 denotes moderate‑to‑high severity, while the EPSS score is not available. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the flaw can be triggered remotely by an attacker with access to the network to send a specially crafted DHCP packet, which would interrupt service availability for all clients associated with the vulnerable DHCP server.
OpenCVE Enrichment