Impact
The vulnerability is an out‑of‑bounds read in the Windows DHCP Server component. When an unauthorized entity sends specially crafted DHCP requests, the server attempts to read memory beyond the bounds of an array, causing the DHCP service to crash. The crash results in a denial of service that affects all clients relying on that DHCP service for IP address assignment. The weakness is a classic out‑of‑bounds read (CWE‑125).
Affected Systems
Affected are Microsoft Windows 10 builds 1607 and 1809 and multiple Windows Server editions, including Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 reflects a moderate severity attack; the EPSS score of 1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote; an outsider who can reach the DHCP port on the network can trigger the read flaw without authentication. Successful exploitation will crash the DHCP service, causing service interruption for all dependent clients.
OpenCVE Enrichment