Windows DHCP Server Information Disclosure Vulnerability
MonitorCVSS 6.5CVE-2026-62718Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Integer underflow vulnerability in Windows DHCP Server allows an unauthorized attacker on an adjacent network to disclose information from server memory. An attacker can send a malformed DHCP packet to trigger the underflow condition, causing the DHCP Server to leak sensitive data in responses. Affects Windows Server 2016, 2019, 2022, 2025 and Windows 10 systems with DHCP Server role enabled.
What this means
What could happen
An attacker on an adjacent network (same subnet) could trigger an integer underflow in Windows DHCP Server to extract sensitive information from memory, such as configuration details, credentials, or other system data.
Who's at risk
Organizations running Windows Server 2016, 2019, 2022, or 2025 with DHCP Server role enabled, and Windows 10 systems acting as DHCP servers. This affects network infrastructure administrators and IT teams responsible for DHCP services in corporate and municipal networks.
How it could be exploited
An attacker sends a specially crafted DHCP request on the local network segment. The Windows DHCP Server processes the malformed packet, triggering an integer underflow that leaks uninitialized or sensitive memory back to the attacker in the DHCP response.
Prerequisites
- Attacker must be on the same network segment (adjacent network) as the DHCP server
- DHCP Server role must be enabled on the target Windows Server or Windows system
Remotely exploitable from adjacent networkNo authentication requiredLow complexity attackInformation disclosure (potential exposure of sensitive memory data)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/8
Do now
0/1WORKAROUNDDisable DHCP Server role on systems where it is not required
Schedule — requires maintenance window
0/6Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9418 or later
All products
HOTFIXUpdate Windows 10 Version 1809 to Build 10.0.17763.9115 or later
HOTFIXUpdate Windows 10 Version 1607 to Build 10.0.14393.9418 or later
Long-term hardening
0/1HARDENINGRestrict DHCP server access to trusted network segments using network segmentation or VLAN isolation
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/741987e1-5b39-48d9-82a7-20eaac1638dcGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.