Impact
An attacker who can send specially crafted DHCP packets to a Windows DHCP Server can exploit a type confusion bug, causing the server to terminate or become unresponsive. This is a classic denial‑of‑service (DoS) vulnerability that can deny service to legitimate clients or disrupt network mobility. The weakness is identified as CWE‑843 (Type Confusion).
Affected Systems
Microsoft Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012, Windows Server 2012 (R2), Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, including Server Core installations for each version.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity DoS risk. While the EPSS score is not available and the vulnerability is not listed in CISA KEV, the likelihood of exploitation remains significant for an attacker who can reach the target DHCP server over the network. The inferred attack vector is remote, requiring network access to send malformed DHCP packets to the vulnerable service.
OpenCVE Enrichment