CVE-2017-8686 is a critical memory corruption vulnerability in the Windows Server DHCP service, affecting Windows Server 2012 (Gold and R2) and Windows Server 2016. An unauthenticated attacker can remotely exploit this flaw with low complexity to achieve arbitrary code execution on the DHCP failover server or cause a denial of service. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness. Despite its high CVSS score of 9.8, it is not currently listed in CISA's KEV catalog, and its EPSS score suggests a relatively low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.