Windows DHCP Server Remote Code Execution Vulnerability

Plan PatchCVSS 8.1CVE-2026-69620Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

Stack-based buffer overflow in Windows DHCP Server allows remote code execution over the network without authentication. Affected versions include Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 versions 1607 and 1809.

What this means
What could happen
An attacker could exploit a buffer overflow in Windows DHCP Server to run code with system privileges on your server, potentially disrupting DHCP services, altering network configurations, or gaining control of critical infrastructure systems that depend on DHCP.
Who's at risk
Water utilities, electric utilities, and other critical infrastructure operators using Windows Server for DHCP services. This affects any organization where DHCP is exposed to untrusted network segments or where network segmentation is incomplete.
How it could be exploited
An attacker on the network sends a specially crafted DHCP packet to a Windows DHCP Server. The packet triggers a stack-based buffer overflow that allows the attacker to execute arbitrary code with the privileges of the DHCP Server service.
Prerequisites
  • Network access to DHCP Server port 67/UDP or port 68/UDP
  • DHCP Server service must be running and exposed to network traffic
  • No credentials required
remotely exploitableno authentication requiredhigh CVSS scoreaffects network services critical to operations
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/6
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to build 10.0.26100.33438 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to build 10.0.14393.9512 or later
Long-term hardening
0/2
HARDENINGRestrict DHCP server network access to only authorized DHCP clients using firewall rules or network segmentation
HARDENINGMonitor DHCP Server event logs for unusual activity or failed DHCP requests
API: /api/v1/advisories/02b6de3f-818a-4d0a-99f9-2b8b8469867d

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Remote Code Execution Vulnerability | CVSS 8.1 - OTPulse