DHCP Server Service Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-48564Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow vulnerability in the Windows DHCP Server service allows an authorized attacker to execute arbitrary code over the network. The vulnerability affects Windows Server 2016, 2019, 2022, 2025, and Windows 10 systems running the DHCP Server service. Microsoft has released patches in the July 2026 security update.

What this means
What could happen
An attacker with DHCP server access credentials could exploit a buffer overflow to run arbitrary code on a Windows server that provides DHCP to your network, potentially disrupting IP address assignment or compromising the server itself.
Who's at risk
Windows IT managers and utilities running DHCP servers on Windows Server 2016, 2019, 2022, or 2025, or Windows 10 systems. DHCP servers are critical for assigning IP addresses to network devices; compromise could disrupt communications across the facility network and OT device connectivity.
How it could be exploited
An attacker with valid credentials on a system with DHCP Server service running can send a malicious network request that triggers a heap-based buffer overflow, allowing them to execute arbitrary code on that server.
Prerequisites
  • Valid credentials for the DHCP server system
  • Network access to the DHCP Server service
  • DHCP Server service installed and running on Windows Server 2016, 2019, 2022, or 2025, or Windows 10
remotely exploitablerequires valid credentialsaffects network infrastructurelow exploitation likelihood per vendor
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to DHCP ports (UDP 67/68) to authorized clients only using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft July 2026 security update to all affected Windows Server and Windows 10 systems with DHCP Server installed
Long-term hardening
0/1
HARDENINGReview and limit credentials for DHCP server administrative access to only personnel who need to manage DHCP
API: /api/v1/advisories/ec6de5b0-fb90-449b-b84c-3eb7d252bf6e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.