Windows DHCP Server Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-58627Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Uncontrolled resource consumption in Windows DHCP Server allows an unauthenticated attacker to deny service over a network. An attacker can crash the DHCP Server by sending specially crafted network packets, preventing IP address assignment to devices and disrupting network connectivity. Affected systems include Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 Version 1607 and 1809. Vendors have released patches for all affected products.

What this means
What could happen
An attacker can crash the Windows DHCP Server with specially crafted network packets, disrupting IP address assignment for all devices on your network and preventing network connectivity for new or reconnecting devices.
Who's at risk
Any organization running Windows DHCP Server (Windows Server 2016, 2019, 2022, or 2025) to manage IP address assignment for network devices. This affects water utilities, electric utilities, and municipalities that rely on DHCP for device connectivity in operational or administrative networks.
How it could be exploited
An attacker sends malformed DHCP packets to port 67/UDP on a Windows DHCP Server without authentication. The server crashes when processing the packet, stopping IP address distribution until the service restarts.
Prerequisites
  • Network access to port 67/UDP on the Windows DHCP Server
  • No authentication required
  • DHCP Server service must be running
remotely exploitableno authentication requiredlow complexityaffects network infrastructure availability
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/5
Do now
0/1
WORKAROUNDRestrict network access to port 67/UDP to authorized DHCP client subnets only using firewall rules
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9339 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33158 or later
API: /api/v1/advisories/b6582852-76f0-46d5-8113-9c7b8d868b19

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Denial of Service Vulnerability | CVSS 7.5 - OTPulse