CVE-2025-21179
published 2025-02-11CVE-2025-21179: DHCP Client Service Denial of Service Vulnerability
PriorityP414medium4.8CVSS 3.1
AVAACHPRNUIRSUCNINAH
EPSS
0.73%
50.0th percentile
DHCP Client Service Denial of Service Vulnerability
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_11_24h2 | < 10.0.26100.3107 | 10.0.26100.3107 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.3194 | 10.0.26100.3194 |
| microsoft | windows_server_2025 | < 10.0.26100.3107 | 10.0.26100.3107 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.3194 | 10.0.26100.3194 |
| msrc | windows_11_version_24h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_24h2_for_x64-based_systems | — | — |
| msrc | windows_server_2025 | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_msrc4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
DHCP Client Service Denial of Service Vulnerability
vendor_msrc·2025-02-11·CVSS 4.8
CVE-2025-21179 [MEDIUM] CWE-125 DHCP Client Service Denial of Service Vulnerability
DHCP Client Service Denial of Service Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications. This is called a machine-in-the-middle (MITM) attack.
FAQ: According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?
This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the same network switch or virtual network.
Windows DHCP Client: Windows DHCP Client
Mic
GHSA
GHSA-rmg9-p599-jx65: DHCP Client Service Denial of Service Vulnerability
ghsa_unreviewed·2025-02-11
CVE-2025-21179 [MEDIUM] CWE-125 GHSA-rmg9-p599-jx65: DHCP Client Service Denial of Service Vulnerability
DHCP Client Service Denial of Service Vulnerability
No detection rules found.
No public exploits indexed.
2025-02-11
Published