Windows DHCP Server Remote Code Execution Vulnerability

Plan PatchCVSS 9.8CVE-2026-50518Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow in Windows DHCP Server allows an unauthenticated attacker to execute arbitrary code remotely by sending a malformed DHCP request over the network. The vulnerability affects Windows Server 2016, 2019, 2022, 2025 and Windows 10 systems running DHCP services. Exploitation is assessed as likely.

What this means
What could happen
An attacker can send a malformed DHCP request over the network to crash the DHCP server or execute arbitrary code on it. In a municipal utility, this could disrupt IP address assignment across your OT network, potentially affecting communication with SCADA systems, RTUs, and other network-dependent devices.
Who's at risk
Windows Server 2016, 2019, 2022, and 2025 installations running DHCP services. Also affects Windows 10 workstations (Version 1607 and 1809) if DHCP relay or server components are enabled. Municipal utilities using Windows-based DHCP infrastructure for OT network management should prioritize patching.
How it could be exploited
An attacker sends a specially crafted DHCP packet to the DHCP server (UDP port 67) with a malformed payload that triggers a heap buffer overflow. The server processes the packet without proper bounds checking, allowing the attacker to overwrite memory and execute commands with DHCP server privileges (typically SYSTEM on Windows Server).
Prerequisites
  • Network access to UDP port 67 on the DHCP server
  • DHCP server enabled and listening for requests
  • No authentication required
remotely exploitableno authentication requiredlow complexityhigh CVSS (9.8)affects network infrastructure
Exploitability
Unlikely to be exploited — EPSS score 1.0%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to UDP port 67 (DHCP) to only authorized networks and subnets that require DHCP services
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Windows security update to all DHCP servers
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate DHCP servers from untrusted networks and the internet
API: /api/v1/advisories/927a126c-4210-4560-a3a4-0e3d984cd656

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Remote Code Execution Vulnerability | CVSS 9.8 - OTPulse