Windows DHCP Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-69547Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

What this means
What could happen
An attacker with network access and valid DHCP administrative credentials could overflow the DHCP server's memory and execute arbitrary commands on the server, potentially gaining control of IP address assignment and network services critical to your facility's operations.
Who's at risk
Windows Server administrators who operate DHCP servers on Windows Server 2016, 2019, 2022, or 2025 should prioritize this update. Impacts organizations using Windows servers as DHCP infrastructure to allocate IP addresses to network equipment, including industrial control systems, building automation, and other networked devices in your facility.
How it could be exploited
An attacker with valid DHCP server administrative credentials could send a specially crafted network packet to the DHCP service to trigger a heap-based buffer overflow, allowing code execution with DHCP server privileges.
Prerequisites
  • Valid DHCP server administrative credentials
  • Network access to the DHCP server on port 67 (UDP) or 547 (IPv6)
  • Windows DHCP Server role installed and running on the target system
Remotely exploitableAuthentication required (authorized attacker)Low complexityHigh CVSS score (8.8)Affects critical network infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/6
Do now
0/1
HARDENINGRestrict DHCP server administrative access to authorized personnel only and monitor administrative account activity logs
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 systems to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 systems to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 systems to Build 10.0.26100.33438 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 systems to Build 10.0.14393.9512 or later
Long-term hardening
0/1
HARDENINGSegment your DHCP server on a protected management network with firewall rules limiting access to authorized networks and devices only
API: /api/v1/advisories/83213f84-850c-41f9-9523-7697acffa01b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Remote Code Execution Vulnerability | CVSS 8.8 - OTPulse