Windows DHCP Server Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-62714Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Integer underflow vulnerability in Windows DHCP Server allows an unauthenticated attacker on an adjacent network to disclose information by sending specially crafted DHCP packets. The vulnerability affects Windows 10 (versions 1607 and 1809) and Windows Server 2016, 2019, 2022, and 2025. Exploitation is considered unlikely by Microsoft. Vendors have released patches for all affected versions.
What this means
What could happen
An attacker on your local network segment could extract sensitive information from the DHCP server, such as lease data or configuration details. This information disclosure does not directly disrupt operations but could be used to plan further attacks.
Who's at risk
Any organization running Windows 10 (versions 1607 or 1809) or Windows Server 2016, 2019, 2022, or 2025 with the DHCP Server role enabled. This primarily affects network administrators and utilities that use Windows-based DHCP infrastructure for IP address management across office and operational networks.
How it could be exploited
An attacker on the same network segment (adjacent network, such as the same switch or subnet) sends crafted DHCP packets designed to trigger an integer underflow in the DHCP server. The server responds with memory contents that were not intended to be disclosed. No authentication is required.
Prerequisites
- Attacker must be on the same local network segment as the affected DHCP server (AV:A)
- No credentials or special privileges required
- The Windows DHCP Server service must be running on the affected system
remotely exploitable within adjacent networkno authentication requiredlow complexity attackinformation disclosure only (no direct operational impact)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict DHCP traffic (UDP port 67/68) at the network edge to only authorized DHCP server and client subnets using firewall or switch ACLs
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the August 2026 Windows security update to Windows 10 (versions 1607 and 1809), Windows Server 2016, 2019, 2022, or 2025
Long-term hardening
0/1HARDENINGSegment DHCP infrastructure into a dedicated management network to limit exposure to untrusted or guest network segments
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/481cc056-6057-4bf5-a7c7-b48749361b20Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.