Windows DHCP Client Denial of Service Vulnerability
MonitorCVSS 6.5CVE-2026-65785Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Uncontrolled resource consumption in Windows DHCP Client allows an attacker on an adjacent network to deny service by sending malformed DHCP responses. The vulnerability affects Windows Server 2025 and Windows 11 systems (versions 24H2, 25H2, and 26H1 for both x64 and ARM64 architectures). Microsoft has released fixes in the 2026-Aug security update with specific build numbers for each affected version.
What this means
What could happen
An attacker on the local network could cause DHCP client services to consume excessive resources, potentially interrupting network connectivity for affected Windows systems. This could affect workstations and servers that depend on DHCP for IP address assignment.
Who's at risk
Windows Server 2025 and Windows 11 systems (versions 24H2, 25H2, and 26H1) running on x64 and ARM64 platforms. Affects any organization using these Windows versions for workstations or servers that rely on DHCP for network configuration, particularly in OT environments where Windows systems manage network infrastructure or serve as engineering workstations.
How it could be exploited
An attacker on the same local network segment crafts and sends specially formed DHCP responses to trigger uncontrolled resource consumption in the Windows DHCP client service. The vulnerable system processes the malicious DHCP data, causing the client to hang, crash, or consume CPU/memory until the service restarts, disrupting network connectivity.
Prerequisites
- Attacker must be on the same local network segment (adjacent network) as the target system
- Target system must be configured to use DHCP for IP address assignment
- No credentials required
- Attack is unauthenticated
remotely exploitable from adjacent networkno authentication requiredlow complexity attackaffects availability of network services
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Do now
0/1WORKAROUNDIf DHCP update cannot be applied immediately, restrict network access to DHCP ports (UDP 67/68) from untrusted network segments using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2025
HOTFIXApply Microsoft 2026-Aug security update to Windows Server 2025, Windows 11 24H2, Windows 11 25H2, and Windows 11 26H1 systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f67021ac-e91e-486f-857e-3d2c73635374Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.