Windows DHCP Server Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-62814Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Integer underflow vulnerability in Windows DHCP Server allows an unauthenticated attacker on an adjacent network to disclose sensitive information by sending malformed DHCP packets. The server's packet handling code fails to properly validate numeric values, causing memory contents (such as DHCP configuration or lease information) to be leaked to the attacker. No authentication or user interaction is required.

What this means
What could happen
An attacker on your network could trigger a bug in the Windows DHCP Server that causes it to reveal sensitive network information, such as DHCP lease details or configuration data, without needing to authenticate.
Who's at risk
Windows administrators who run the DHCP Server role on Windows Server 2016, 2019, 2022, or 2025, or Windows 10 systems (versions 1607, 1809 or later). This affects any organization using Windows for DHCP services instead of dedicated appliances—common in smaller IT shops and municipal/utility networks that run DHCP on domain controllers.
How it could be exploited
An attacker positioned on the same network segment as your DHCP server could send specially crafted DHCP packets that trigger an integer underflow in the server's packet handling code. This causes the server to leak memory contents containing network configuration or other sensitive data that can be read off the network.
Prerequisites
  • Network access to DHCP server on adjacent network segment (ARP-reachable)
  • No authentication required
  • DHCP Server role must be running on affected Windows system
remotely exploitableno authentication requiredlow complexityaffects network infrastructure service
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/2
Do now
0/1
WORKAROUNDIf immediate patching is not possible, restrict network access to port 67/UDP (DHCP) to trusted DHCP clients and administrative networks using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft's 2026-Aug security update to all affected Windows 10 and Windows Server systems
API: /api/v1/advisories/44abef8d-c7e1-4977-b96f-4d626214d6f9

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.