Windows DHCP Client Denial of Service Vulnerability

MonitorCVSS 6.5CVE-2026-65785Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Uncontrolled resource consumption in Windows DHCP Client allows an attacker on an adjacent network to deny service by sending malformed DHCP responses. The vulnerability affects Windows Server 2025 and Windows 11 systems (versions 24H2, 25H2, and 26H1 for both x64 and ARM64 architectures). Microsoft has released fixes in the 2026-Aug security update with specific build numbers for each affected version.

What this means
What could happen
An attacker on the local network could cause DHCP client services to consume excessive resources, potentially interrupting network connectivity for affected Windows systems. This could affect workstations and servers that depend on DHCP for IP address assignment.
Who's at risk
Windows Server 2025 and Windows 11 systems (versions 24H2, 25H2, and 26H1) running on x64 and ARM64 platforms. Affects any organization using these Windows versions for workstations or servers that rely on DHCP for network configuration, particularly in OT environments where Windows systems manage network infrastructure or serve as engineering workstations.
How it could be exploited
An attacker on the same local network segment crafts and sends specially formed DHCP responses to trigger uncontrolled resource consumption in the Windows DHCP client service. The vulnerable system processes the malicious DHCP data, causing the client to hang, crash, or consume CPU/memory until the service restarts, disrupting network connectivity.
Prerequisites
  • Attacker must be on the same local network segment (adjacent network) as the target system
  • Target system must be configured to use DHCP for IP address assignment
  • No credentials required
  • Attack is unauthenticated
remotely exploitable from adjacent networkno authentication requiredlow complexity attackaffects availability of network services
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9106
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9168
Windows Server 2025All versionsBuild 10.0.26100.33296
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2704
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2704
Remediation & Mitigation
0/2
Do now
0/1
WORKAROUNDIf DHCP update cannot be applied immediately, restrict network access to DHCP ports (UDP 67/68) from untrusted network segments using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXApply Microsoft 2026-Aug security update to Windows Server 2025, Windows 11 24H2, Windows 11 25H2, and Windows 11 26H1 systems
API: /api/v1/advisories/f67021ac-e91e-486f-857e-3d2c73635374

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.