Windows DHCP Server Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-62742Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

An integer underflow vulnerability in Windows DHCP Server allows an unauthenticated attacker on the same network segment to disclose sensitive information from server memory. The vulnerability requires no user interaction and can be triggered through specially crafted DHCP requests. Affected versions include Windows Server 2016, 2019, 2022, 2025, and Windows 10 versions 1607 and 1809.

What this means
What could happen
An attacker on the same network segment could trigger an integer underflow in Windows DHCP Server to read sensitive memory contents, potentially exposing network configuration details, credentials, or other system information.
Who's at risk
Water utilities, power companies, and other critical infrastructure facilities using Windows Server 2016, 2019, 2022, or 2025 as DHCP servers should prioritize patching. Organizations running Windows 10 on networked systems with DHCP Server enabled are also affected. This impacts any facility where DHCP is deployed for automated IP address assignment to operational technology or IT networks.
How it could be exploited
An attacker must be on the same network segment (AV:A - adjacent network access). They send a specially crafted DHCP request to the server that triggers an integer underflow condition, causing the DHCP service to leak information from its memory. No authentication or user interaction is required.
Prerequisites
  • Attacker must be on the same network segment as the DHCP server
  • DHCP Server service must be running and reachable
remotely exploitable from adjacent networkno authentication requiredlow complexity attackinformation disclosure of sensitive dataaffects network infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/6
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
All products
HOTFIXUpdate Windows 10 Version 1607 to Build 10.0.14393.9418 or later
HOTFIXUpdate Windows 10 Version 1809 to Build 10.0.17763.9115 or later
Long-term hardening
0/1
HARDENINGRestrict DHCP server network access to authorized clients only using network segmentation or firewall rules
API: /api/v1/advisories/014ec225-8a71-418c-bdaa-775e757b48dc

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Information Disclosure Vulnerability | CVSS 6.5 - OTPulse