Windows DHCP Server Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-62716Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Integer underflow vulnerability in Windows DHCP Server allows an unauthenticated attacker on an adjacent network segment to disclose information from server memory via a specially crafted DHCP packet. Affects Windows Server 2016, 2019, 2022, 2025 and Windows 10 versions 1607 and 1809. Exploitation is assessed as unlikely. Microsoft has released patches for all affected versions.
What this means
What could happen
An attacker on the same network segment could trigger an integer underflow in the DHCP Server, potentially reading sensitive information from memory. This could expose configuration data or system secrets if your DHCP server is exposed to untrusted networks.
Who's at risk
Windows Server 2016, 2019, 2022, and 2025 (all editions including Server Core), and Windows 10 (versions 1607 and 1809). Any organization using Windows DHCP servers for IP address allocation should assess if this patch applies to their infrastructure. This is particularly relevant for municipal utilities and water authorities that manage IT infrastructure with Windows-based DHCP services.
How it could be exploited
An attacker with network access to a Windows DHCP Server (typically UDP port 67/68) sends a specially crafted DHCP packet that triggers an integer underflow condition. This causes the server to read and return memory contents that should not be accessible, leaking information over the network.
Prerequisites
- Network access to the Windows DHCP Server on the same network segment (adjacent network)
- No authentication required
- The DHCP Server service must be running
remotely exploitableno authentication requiredlow complexityadjacent network access onlyinformation disclosure (not code execution)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/8
Do now
0/1HARDENINGRestrict DHCP server network access: Use firewall rules to limit DHCP traffic (UDP ports 67-68) to authorized subnets and devices only
Schedule — requires maintenance window
0/6Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9418 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
All products
HOTFIXUpdate Windows 10 Version 1607 to Build 10.0.14393.9418 or later
HOTFIXUpdate Windows 10 Version 1809 to Build 10.0.17763.9115 or later
Long-term hardening
0/1HARDENINGIsolate DHCP servers on a dedicated, managed network segment separate from untrusted or guest networks
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/4615d15b-6b9f-4be8-bbd1-3c5e2c57f906Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.