Windows DHCP Server Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-69547Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
What this means
What could happen
An attacker with network access and valid DHCP administrative credentials could overflow the DHCP server's memory and execute arbitrary commands on the server, potentially gaining control of IP address assignment and network services critical to your facility's operations.
Who's at risk
Windows Server administrators who operate DHCP servers on Windows Server 2016, 2019, 2022, or 2025 should prioritize this update. Impacts organizations using Windows servers as DHCP infrastructure to allocate IP addresses to network equipment, including industrial control systems, building automation, and other networked devices in your facility.
How it could be exploited
An attacker with valid DHCP server administrative credentials could send a specially crafted network packet to the DHCP service to trigger a heap-based buffer overflow, allowing code execution with DHCP server privileges.
Prerequisites
- Valid DHCP server administrative credentials
- Network access to the DHCP server on port 67 (UDP) or 547 (IPv6)
- Windows DHCP Server role installed and running on the target system
Remotely exploitableAuthentication required (authorized attacker)Low complexityHigh CVSS score (8.8)Affects critical network infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/6
Do now
0/1HARDENINGRestrict DHCP server administrative access to authorized personnel only and monitor administrative account activity logs
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 systems to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 systems to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 systems to Build 10.0.26100.33438 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 systems to Build 10.0.14393.9512 or later
Long-term hardening
0/1HARDENINGSegment your DHCP server on a protected management network with firewall rules limiting access to authorized networks and devices only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/83213f84-850c-41f9-9523-7697acffa01bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.