Windows DHCP Server Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-69342Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read vulnerability in Windows DHCP Server allows an unauthorized network attacker to trigger a denial of service condition without credentials. Affected versions include Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 versions 1607 and 1809. Microsoft has released patches for all affected versions via the September 2026 security update.
What this means
What could happen
A network attacker can crash the Windows DHCP Server service without credentials, disrupting IP address assignment and network connectivity for connected devices. This could prevent plant equipment from obtaining network leases and cause communication failures across your operations network.
Who's at risk
Windows Server installations running DHCP Server service, including Windows Server 2016, 2019, 2022, and 2025. Organizations with Windows Server-based DHCP infrastructure supporting plant networks, particularly in utilities and municipalities where IP management is critical to device communication.
How it could be exploited
An attacker on the network sends a malformed DHCP packet to the server. The DHCP Server process reads memory out of bounds, crashes, and stops responding to DHCP requests. Connected devices and new equipment cannot obtain IP addresses and lose network connectivity.
Prerequisites
- Network access to DHCP server port 67/UDP
- DHCP Server service enabled and listening on the network
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects network operationsactively used in OT environments
Exploitability
Some exploitation risk — EPSS score 1.1%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/6
Do now
0/1WORKAROUNDRestrict DHCP server access via firewall to only authorized network segments and limit UDP port 67 inbound to trusted subnets
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9512 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
Long-term hardening
0/1HARDENINGSegregate DHCP servers and critical OT network segments using network access controls to reduce exposure surface
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/97f16354-0db3-43b1-8d30-9a61c94f220aGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.