Windows DHCP Server Remote Code Execution Vulnerability
Plan PatchCVSS 8CVE-2026-69412Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Stack-based buffer overflow in Windows DHCP Server allows an authenticated attacker with network access to execute code on adjacent networks. The vulnerability requires valid network credentials and affects Windows Server 2016, 2019, 2022, 2025, and Windows 10 systems running DHCP services. Microsoft has released patches for all affected versions.
What this means
What could happen
An authenticated attacker on the same network segment could overflow the DHCP server's memory, potentially running commands with DHCP service privileges—which could disrupt network address assignment for all connected devices on your network.
Who's at risk
Windows Server administrators running DHCP services on Server 2016, 2019, 2022, or 2025, including those managing network infrastructure in municipal utilities, water authorities, or any facility where DHCP assigns addresses to operational technology devices. Also affects Windows 10 systems running DHCP server roles.
How it could be exploited
An attacker with valid network credentials sends a specially crafted DHCP packet to the DHCP server on port 67/UDP. The malicious packet triggers a stack buffer overflow in the DHCP service, allowing the attacker to inject and execute arbitrary code with the privileges of the DHCP service account.
Prerequisites
- Network access to DHCP server on port 67/UDP (same network segment or adjacent network)
- Valid credentials on the network domain
- DHCP server must be running and handling DHCP requests
requires network adjacency (same or adjacent network segment)authentication requiredlow exploit probability (0.5% EPSS)affects network availability and DHCP service continuity
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to DHCP ports (UDP 67/68) to trusted devices and authorized DHCP clients only using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's 2026-September security update to all Windows Server DHCP servers (Build 10.0.17763.9245 for Server 2019, Build 10.0.20348.5622 for Server 2022, Build 10.0.26100.33438 for Server 2025)
Long-term hardening
0/1HARDENINGReview and limit domain accounts with network access to the DHCP server segment
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/a07d3f9a-c3d2-4711-a7c8-8e6de91b55eeGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.