Windows DHCP Server Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-69266Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
Integer overflow in Windows DHCP Server (versions 2016, 2019, 2022, 2025, and Windows 10 1607 and 1809) allows an unauthorized attacker to execute arbitrary code by sending a specially crafted network packet. The DHCP service processes the malformed packet without proper bounds checking on an integer value, leading to memory corruption and code execution. Exploitation is considered less likely, but the vulnerability requires no user interaction and no authentication.
What this means
What could happen
An attacker with network access to a Windows DHCP server could send a specially crafted packet that causes an integer overflow, allowing them to execute arbitrary code on the server. This could give the attacker full control over the DHCP service, which could disrupt network address assignment or be used as a foothold to attack other systems on your network.
Who's at risk
Water utilities and municipal electric utilities that use Windows Server as DHCP servers (2016, 2019, 2022, 2025) in their IT infrastructure. This is particularly important if the DHCP server is directly connected to or has visibility from the network where field devices, SCADA systems, or engineering workstations are located. Organizations using Windows 10 machines as DHCP servers in smaller deployments are also affected.
How it could be exploited
An attacker sends a malformed DHCP packet over the network to a vulnerable DHCP server. The packet triggers an integer overflow in the DHCP service processing logic, allowing the attacker to write arbitrary code into memory and execute it with DHCP service privileges. No user interaction or authentication is required.
Prerequisites
- Network access to the DHCP server on port 67/68 (UDP)
- Target system must be running a vulnerable version of Windows Server (2016, 2019, 2022, 2025) or Windows 10 (versions 1607, 1809)
- DHCP service must be enabled and running
remotely exploitableno authentication requiredlow complexity attackaffects network infrastructure availability
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/8
Do now
0/1WORKAROUNDRestrict network access to DHCP ports (67/68 UDP) to only authorized DHCP clients and trusted networks using firewall rules
Schedule — requires maintenance window
0/7Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9512 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1809 (x64) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1607 (32-bit) to Build 10.0.14393.9512 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ec2299d7-8dfe-4f55-a1a1-ff82279c4b93Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.