Windows DHCP Server Denial of Service Vulnerability
MonitorCVSS 5.7CVE-2026-69405Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A memory leak in Windows DHCP Server allows an authorized local network attacker to exhaust DHCP server memory and force a denial of service. The vulnerability exists in Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 versions 1607 and 1809. Exploitation requires adjacent network access and user-level credentials. All affected versions have fixes available in September 2026 security updates.
What this means
What could happen
A DHCP server running a vulnerable Windows version can be crashed by a local network attacker with user-level credentials, causing loss of IP address assignment and potential disruption to network operations including any SCADA or remote monitoring systems dependent on dynamic IP configuration.
Who's at risk
Utilities and facilities using Windows Server 2016, 2019, 2022, or 2025 as DHCP servers should prioritize patching. This includes any network that depends on Windows-based DHCP for IP assignment to control systems, RTUs, sensors, or remote monitoring devices. Organizations with industrial networks sharing Windows infrastructure are at risk.
How it could be exploited
An attacker on the same local network (adjacent network) with regular user credentials sends a crafted DHCP request to the Windows DHCP server. This triggers a memory leak in the DHCP service that eventually exhausts available memory, causing the service or system to crash and stop responding to legitimate DHCP requests.
Prerequisites
- Network access to DHCP server (UDP port 67) from same local network segment
- User-level credentials or ability to send packets as a local network device
- DHCP server role enabled on vulnerable Windows system
requires local network accessrequires user-level credentialsaffects DHCP service availabilitymedium severity
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply September 2026 Windows security updates to all DHCP servers
Long-term hardening
0/2HARDENINGRestrict DHCP server network access to only authorized subnets and devices using network segmentation or DHCP snooping on network switches
HARDENINGMonitor DHCP server memory usage and process availability to detect denial-of-service conditions and alert operations staff
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/64596c02-6c98-42c5-9eb0-864c334fee0eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.