Windows DHCP Server Information Disclosure Vulnerability

MonitorCVSS 6.5CVE-2026-69297Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Windows DHCP Server stores passwords in a recoverable format, allowing an authorized attacker to disclose sensitive information over the network. DHCP is a foundational service for assigning IP addresses to devices, and compromise of DHCP credentials could lead to unauthorized administrative access or network manipulation.

What this means
What could happen
An attacker with network access and valid credentials could extract stored passwords from your DHCP server, potentially gaining administrative control over IP address assignment for your entire network, including critical OT devices.
Who's at risk
Organizations running Windows DHCP Server for network IP address assignment, including utilities and municipalities using Windows Server for DHCP infrastructure. Affects Windows 10 Version 1607 and 1809, Windows Server 2016, 2019, 2022, and 2025. This is critical for any organization relying on Windows-based DHCP, as DHCP controls IP assignment for all network devices including OT systems.
How it could be exploited
An attacker with valid domain or local credentials on the DHCP server system could connect to the DHCP service, access stored password data in recoverable format, and extract cleartext or easily reversible credentials. This could then be used to authenticate as an administrator to manipulate DHCP configuration or other network services.
Prerequisites
  • Valid domain or local user credentials on a Windows system running DHCP Server
  • Network access to the DHCP Server system
  • Physical or administrative access to the DHCP server, or ability to authenticate remotely as an authorized user
information disclosurerequires valid credentialsaffects network infrastructurelow exploit probability
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/7
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1607 to Build 10.0.14393.9512 or later
HOTFIXUpdate Windows 10 Version 1809 to Build 10.0.17763.9245 or later
Long-term hardening
0/2
HARDENINGRestrict network access to DHCP Server systems to only authorized administrative personnel and infrastructure
HARDENINGEnforce strong authentication (MFA or certificate-based) for administrative access to DHCP servers
API: /api/v1/advisories/ef53e241-5f21-4f0f-a401-3763d2ffbd93

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.