Windows DHCP Server Denial of Service Vulnerability

MonitorCVSS 5.7CVE-2026-69637Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Out-of-bounds read vulnerability in Windows DHCP Server allows an authorized attacker on an adjacent network to crash the DHCP service by sending a malformed DHCP packet. Affected versions include Windows 10 (1607, 1809), Windows Server 2016, 2019, 2022, and 2025. The vulnerability causes denial of service to DHCP functionality, preventing new devices from obtaining IP addresses.

What this means
What could happen
An attacker on your local network segment could crash the Windows DHCP server by sending malformed DHCP packets, disrupting IP address assignment for devices connecting to that network.
Who's at risk
Organizations running Windows Server 2016, 2019, 2022, or 2025 as DHCP servers should prioritize this fix. Also affects Windows 10 systems with DHCP server capability. This impacts any utility, municipality, or facility that relies on Windows-based DHCP for network infrastructure or OT device IP management.
How it could be exploited
An attacker with access to the same network segment (adjacent network) sends a specially crafted DHCP packet to a Windows DHCP server. The out-of-bounds read causes the DHCP service to crash, taking down DHCP services until the server is manually restarted.
Prerequisites
  • Network access to the DHCP server on the same network segment (not remotely exploitable)
  • Local network access to send DHCP packets to the server
  • Requires authenticated/authorized access to the network
requires local network accesslow EPSS score (0.7%)low exploitation likelihoodaffects network infrastructure (DHCP service denial)medium severity (service disruption, not asset compromise)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to DHCP ports (UDP 67/68) to only authorized DHCP clients and administrative networks using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply Windows security update for September 2026 (or later) to all affected Windows systems running DHCP server role: Windows 10 (1607, 1809), Windows Server 2016, 2019, 2022, 2025
Long-term hardening
0/1
HARDENINGIsolate DHCP servers on a dedicated management network segment separate from general operational networks
API: /api/v1/advisories/370054d9-c320-4200-9735-e7edddd0a919

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Denial of Service Vulnerability | CVSS 5.7 - OTPulse