Windows DHCP Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-62823Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker on the adjacent network to execute code with DHCP server privileges. The vulnerability is triggered by a specially crafted DHCP packet that overflows memory on the DHCP server. All supported versions of Windows Server 2016, 2019, 2022, 2025 and Windows 10 systems with the DHCP Server role are affected. Microsoft has released patches for all affected versions.

What this means
What could happen
An attacker on your network could send a specially crafted DHCP request to a Windows DHCP server to gain control and run arbitrary code on it. If your DHCP server manages network configuration for critical operational devices, this could disrupt network access to PLCs, RTUs, or other control systems.
Who's at risk
Windows Server administrators and IT staff managing DHCP services for any network infrastructure, especially those with operational technology devices (sensors, PLCs, controllers) that depend on DHCP-assigned network configuration. Affects Windows Server 2016, 2019, 2022, 2025 and Windows 10 systems running DHCP Server role.
How it could be exploited
An attacker on the same network segment as your DHCP server sends a malformed DHCP packet that overflows the server's memory, allowing them to inject and execute commands. No authentication is required. The attacker needs network access to reach the DHCP service (typically port 67/68 UDP).
Prerequisites
  • Adjacent network access (same subnet or VLAN as DHCP server)
  • No authentication required
  • DHCP Server role enabled and running on Windows Server or Windows 10
remotely exploitableno authentication requiredlow complexityaffects network infrastructure critical to OT operationshigh CVSS score (8.8)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGRestrict network access to DHCP ports (UDP 67/68) to only authorized DHCP clients and trusted network segments; use firewall rules or network segmentation to limit which devices can send DHCP requests
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXApply Microsoft security update 2026-Aug to Windows DHCP servers: Windows Server 2019 build 10.0.17763.9115 or later, Windows Server 2022 build 10.0.20348.5499 or later, Windows Server 2025 build 10.0.26100.33296 or later
Long-term hardening
0/1
HARDENINGImplement network segmentation so DHCP servers are not reachable from untrusted network segments or guest VLANs
API: /api/v1/advisories/516680a3-7bae-4823-bf3b-d557483eee25

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Remote Code Execution Vulnerability | CVSS 8.8 - OTPulse