DHCP Server Service Remote Code Execution Vulnerability

Plan PatchCVSS 9.8CVE-2026-56159Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow vulnerability in Windows DHCP Server service allows unauthorized remote code execution. An attacker can send a specially crafted DHCP packet to execute arbitrary code on affected Windows servers with full system privileges, potentially taking control of the server and disrupting DHCP services that assign IP addresses to networked devices.

What this means
What could happen
A heap buffer overflow in Windows DHCP Server allows an attacker to execute arbitrary code on the affected server with full system privileges. This could let an attacker take complete control of the server, modify network configurations, or disrupt DHCP services that assign IP addresses to devices across your facility.
Who's at risk
Water and electric utilities that use Windows DHCP Servers for network management. This affects Windows Server 2016, 2019, 2022, 2025, and Windows 10 systems running the DHCP service. Any facility where DHCP assigns IP addresses to operational equipment (RTUs, PLCs, HMI systems, field devices) depends on this service.
How it could be exploited
An attacker on your network sends a specially crafted DHCP request to a Windows DHCP Server. The malformed packet triggers a buffer overflow in the DHCP service memory, allowing the attacker to inject and execute arbitrary code with system-level privileges. No authentication is required; the attacker only needs network access to the DHCP server port (typically UDP 67).
Prerequisites
  • Network access to DHCP Server on UDP port 67
  • Target must be running Windows DHCP Server role or service on an affected Windows version
remotely exploitableno authentication requiredlow complexitycritical CVSS score (9.8)affects network infrastructure that supports OT devices
Exploitability
Unlikely to be exploited — EPSS score 1.0%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/2
Do now
0/1
WORKAROUNDIf immediate patching is not possible, restrict network access to DHCP Server (UDP port 67) from untrusted or external networks using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the 2026-Jul security update to all Windows DHCP Servers (Windows Server 2016, 2019, 2022, or 2025)
API: /api/v1/advisories/7454e2c0-2581-42d9-ba67-4dbbce46ee37

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

DHCP Server Service Remote Code Execution Vulnerability | CVSS 9.8 - OTPulse