Back

CVE-2017-8686

CRITICAL

The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows Server DHCP service, aka "Windows DHCP Server Remote Code Execution Vulnerability".

Published: Sep 13, 2017 Modified: Jun 17, 2026
CWE-119

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
microsoft windows_server_2012 -
microsoft windows_server_2012 r2
microsoft windows_server_2016 *

GitHub Security Advisory GHSA-27h2-vr79-q7cq

The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 27.50%

Top 2% most likely to be exploited

Threat Score 47.4 / 100

Data Sources

NVD EPSS GitHub