Windows DHCP Server Denial of Service Vulnerability
MonitorCVSS 5.7CVE-2026-69637Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Out-of-bounds read vulnerability in Windows DHCP Server allows an authorized attacker on an adjacent network to crash the DHCP service by sending a malformed DHCP packet. Affected versions include Windows 10 (1607, 1809), Windows Server 2016, 2019, 2022, and 2025. The vulnerability causes denial of service to DHCP functionality, preventing new devices from obtaining IP addresses.
What this means
What could happen
An attacker on your local network segment could crash the Windows DHCP server by sending malformed DHCP packets, disrupting IP address assignment for devices connecting to that network.
Who's at risk
Organizations running Windows Server 2016, 2019, 2022, or 2025 as DHCP servers should prioritize this fix. Also affects Windows 10 systems with DHCP server capability. This impacts any utility, municipality, or facility that relies on Windows-based DHCP for network infrastructure or OT device IP management.
How it could be exploited
An attacker with access to the same network segment (adjacent network) sends a specially crafted DHCP packet to a Windows DHCP server. The out-of-bounds read causes the DHCP service to crash, taking down DHCP services until the server is manually restarted.
Prerequisites
- Network access to the DHCP server on the same network segment (not remotely exploitable)
- Local network access to send DHCP packets to the server
- Requires authenticated/authorized access to the network
requires local network accesslow EPSS score (0.7%)low exploitation likelihoodaffects network infrastructure (DHCP service denial)medium severity (service disruption, not asset compromise)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to DHCP ports (UDP 67/68) to only authorized DHCP clients and administrative networks using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply Windows security update for September 2026 (or later) to all affected Windows systems running DHCP server role: Windows 10 (1607, 1809), Windows Server 2016, 2019, 2022, 2025
Long-term hardening
0/1HARDENINGIsolate DHCP servers on a dedicated management network segment separate from general operational networks
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/370054d9-c320-4200-9735-e7edddd0a919Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.