Windows DHCP Server Remote Code Execution Vulnerability
Plan PatchCVSS 7.5CVE-2026-50685Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
Double free vulnerability in Windows DHCP Server allows an authenticated attacker to execute arbitrary code over the network. Affects Windows 10 (versions 1607, 1809), Windows Server 2016, 2019, 2022, and 2025. Exploitation is assessed as unlikely. Vendors have released patches for all affected products.
What this means
What could happen
An authenticated attacker with network access to a Windows DHCP server could trigger a double-free memory vulnerability to execute arbitrary code with system privileges, potentially disrupting network configuration services or gaining control of the server.
Who's at risk
This affects IT administrators and network engineers responsible for Windows Server DHCP infrastructure, particularly those managing Windows Server 2016, 2019, 2022, or 2025, and Windows 10 systems providing DHCP services. Municipal utilities, water authorities, and other critical infrastructure operators running these systems for network management should assess exposure.
How it could be exploited
An attacker with valid credentials on the network sends a specially crafted DHCP packet or network request to the DHCP server. The double-free vulnerability in memory management allows the attacker to execute arbitrary code with the privileges of the DHCP service. This could enable the attacker to alter IP address assignments, disable DHCP services to devices on your network, or gain control of the server itself.
Prerequisites
- Valid network user credentials or domain account
- Network connectivity to TCP/UDP port 67/68 (DHCP)
- DHCP Server role enabled and running on affected Windows Server or Windows 10/11 system
Remotely exploitableRequires authentication (valid network credentials)Medium EPSS score (~0.6%)Affects server infrastructureAuthentication requirement reduces immediate threat
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (10)
10 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict DHCP server network access: firewall rules to allow DHCP traffic only from authorized DHCP clients and management networks
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the 2026-July security update to all Windows Server 2016, 2019, 2022, 2025 and Windows 10 systems running DHCP Server role
Long-term hardening
0/1HARDENINGDisable DHCP Server role on systems that do not require it
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/33ab2a4c-709c-458e-8684-c06e9b654958Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.