Windows DHCP Server Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-62715Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Integer underflow vulnerability in Windows DHCP Server allows an unauthorized attacker on an adjacent network to disclose information without authentication. The vulnerability exists in Windows 10 Version 1607 and 1809, Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches for all affected versions.

What this means
What could happen
An attacker on the same local network could extract sensitive information from the DHCP server (such as IP address assignments, lease information, or other network configuration details). This does not allow process disruption but could enable further reconnaissance of your network.
Who's at risk
Organizations running Windows Server 2016, 2019, 2022, or 2025 as a DHCP server, or Windows 10 systems with DHCP Server role enabled. This affects network infrastructure teams responsible for IP address management and allocation in enterprise or municipal networks.
How it could be exploited
An attacker on the same network segment (adjacent network) sends specially crafted DHCP messages to the Windows DHCP server. The integer underflow vulnerability causes the server to disclose information in its response that should not be visible to unauthorized users.
Prerequisites
  • Network access to the DHCP server on the same local network segment (AV:A)
  • No authentication required
  • DHCP server must be running on the affected Windows system
remotely exploitable (adjacent network)no authentication requiredlow complexity attackdefault DHCP server operation exposes this
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/7
Do now
0/2
WORKAROUNDRestrict network access to the DHCP server to authorized administrative and client networks only using firewall rules or network segmentation
WORKAROUNDIf DHCP server is not needed, disable the DHCP Server service
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit) to Build 10.0.17763.9115 or later
HOTFIXUpdate Windows 10 Version 1809 (x64) to Build 10.0.17763.9115 or later
API: /api/v1/advisories/ee91df39-4c25-44d3-a48a-28c1e7daeeca

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Information Disclosure Vulnerability | CVSS 6.5 - OTPulse