Impact
The vulnerability is an out‑of‑bounds read in the Windows DHCP Server. An unauthorized attacker can trigger it by sending crafted DHCP packets, which causes the server to crash and deny service across the network. This flaw is a memory safety error (CWE‑125) and results in loss of availability for network clients that depend on DHCP.
Affected Systems
Microsoft Windows 10 version 1607, Microsoft Windows 10 version 1809, Microsoft Windows Server 2012, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Windows Server 2025 (including core installations)
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑to‑high severity. The exploit requires network access to the DHCP server; an attacker on the same subnet can send malicious packets, but no user interaction is needed. EPSS is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can crash the DHCP service, it poses a significant risk to availability in environments that rely on a single DHCP infrastructure.
OpenCVE Enrichment