DHCP Server Service Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-48564Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow vulnerability in the Windows DHCP Server service allows an authorized attacker to execute arbitrary code over the network. The vulnerability affects Windows Server 2016, 2019, 2022, 2025, and Windows 10 systems running the DHCP Server service. Microsoft has released patches in the July 2026 security update.
What this means
What could happen
An attacker with DHCP server access credentials could exploit a buffer overflow to run arbitrary code on a Windows server that provides DHCP to your network, potentially disrupting IP address assignment or compromising the server itself.
Who's at risk
Windows IT managers and utilities running DHCP servers on Windows Server 2016, 2019, 2022, or 2025, or Windows 10 systems. DHCP servers are critical for assigning IP addresses to network devices; compromise could disrupt communications across the facility network and OT device connectivity.
How it could be exploited
An attacker with valid credentials on a system with DHCP Server service running can send a malicious network request that triggers a heap-based buffer overflow, allowing them to execute arbitrary code on that server.
Prerequisites
- Valid credentials for the DHCP server system
- Network access to the DHCP Server service
- DHCP Server service installed and running on Windows Server 2016, 2019, 2022, or 2025, or Windows 10
remotely exploitablerequires valid credentialsaffects network infrastructurelow exploitation likelihood per vendor
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to DHCP ports (UDP 67/68) to authorized clients only using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft July 2026 security update to all affected Windows Server and Windows 10 systems with DHCP Server installed
Long-term hardening
0/1HARDENINGReview and limit credentials for DHCP server administrative access to only personnel who need to manage DHCP
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ec6de5b0-fb90-449b-b84c-3eb7d252bf6eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.