Windows DHCP Server Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-62720Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Integer underflow in Windows DHCP Server allows an unauthorized attacker on an adjacent network to disclose information. The vulnerability affects Windows 10 Versions 1607 and 1809, and Windows Server 2016, 2019, 2022, and 2025. Exploitation is considered unlikely. The flaw enables network information disclosure through specially crafted DHCP packets processed by the affected DHCP Server.

What this means
What could happen
An attacker on your local network could exploit an integer underflow in the Windows DHCP Server to extract sensitive network information, potentially revealing IP configuration details or other data that could aid further attacks.
Who's at risk
Organizations running Windows DHCP Server roles on Windows Server 2016, 2019, 2022, or 2025, as well as those using Windows 10 Version 1607 or 1809 as DHCP servers. This affects any IT infrastructure using Microsoft DHCP for IP address assignment in municipal networks, water authority networks, or utility operations.
How it could be exploited
An attacker positioned on the same local network segment sends specially crafted DHCP packets to the DHCP Server. The integer underflow flaw in packet processing causes the server to disclose information that should not be accessible, which the attacker can capture and analyze to learn about your network configuration.
Prerequisites
  • Network access to DHCP server on the same local network segment (adjacent network)
  • No authentication required
  • Windows DHCP Server role must be installed and running
remotely exploitableno authentication requiredlow complexityadjacent network access requiredinformation disclosure only (no confidentiality impact on operations)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/7
Do now
0/1
WORKAROUNDRestrict DHCP server network access using firewall rules to block untrusted clients on adjacent network segments
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
All products
HOTFIXUpdate Windows 10 Version 1809 32-bit systems to Build 10.0.17763.9115 or later
HOTFIXUpdate Windows 10 Version 1809 x64-based systems to Build 10.0.17763.9115 or later
Long-term hardening
0/1
HARDENINGSegment network to isolate DHCP servers from untrusted network segments where possible
API: /api/v1/advisories/7a6e3d72-48db-4037-9733-a117f5888042

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Information Disclosure Vulnerability | CVSS 6.5 - OTPulse