Windows DHCP Client Remote Code Execution Vulnerability
Plan PatchCVSS 8.4CVE-2026-54128Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A use-after-free vulnerability in the Windows DHCP Client service allows an attacker with local access to execute arbitrary code with system-level privileges. The flaw can be triggered by processing a specially crafted DHCP response or network packet. This affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
An attacker with local access to a Windows machine can execute arbitrary code through the DHCP Client service, potentially gaining full system control and the ability to modify or disrupt any networked OT devices or automation systems that machine communicates with.
Who's at risk
Windows system administrators and industrial sites that rely on Windows 10, Windows 11, or Windows Server (2016, 2019, 2022, 2025) machines for engineering workstations, HMI hosts, data historians, or any device that communicates with PLCs, RTUs, or other OT equipment. Particularly critical if these machines function as gateways between corporate networks and production control systems.
How it could be exploited
An attacker already on the Windows host (via prior compromise, physical access, or lateral movement) triggers a use-after-free memory flaw in the DHCP Client by sending a specially crafted network packet or forcing the system to process a malicious DHCP response. This causes code execution with the same privileges as the DHCP Client service (typically local system level).
Prerequisites
- Local access to a Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 machine
- DHCP Client service must be running (enabled by default on most Windows systems)
- System must not have the July 2026 security update installed
Remotely exploitable via DHCP network trafficLocal code execution with high impact (full system compromise)Affects all common Windows versionsVendor fix available but requires patch deployment and system restart
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the July 2026 Windows security update to all affected Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
Long-term hardening
0/2WORKAROUNDDisable or restrict the DHCP Client service if static IP addressing is used instead
HARDENINGSegment engineering workstations and OT networks from general IT systems to limit lateral movement if a Windows machine is compromised
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f6e05dd8-80f4-4939-b43e-689e9ba2cfa2Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.