Windows DHCP Server Denial of Service Vulnerability

MonitorCVSS 5.7CVE-2026-69679Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in Windows DHCP Server allows an authorized attacker on the same network segment to cause a denial of service by crafting malicious DHCP messages. The vulnerability affects Windows 10 and Windows Server versions 2016 through 2025.

What this means
What could happen
An attacker with local network access could crash your DHCP server, preventing devices from obtaining IP addresses and disrupting network connectivity for all connected equipment until the service restarts.
Who's at risk
Water authorities and utilities running Windows DHCP servers (Windows Server 2016, 2019, 2022, or 2025, or Windows 10 endpoints as DHCP servers) should prioritize this. Impact is moderate because DHCP outages disrupt network connectivity for all devices, including control systems, though the attack requires local network access and valid credentials.
How it could be exploited
An attacker on your local network segment (adjacent network) with valid DHCP client or user credentials sends a specially crafted DHCP message to the DHCP server, triggering an out-of-bounds read that crashes the DHCP service.
Prerequisites
  • Attacker must be on the same network segment (adjacent network) as the DHCP server
  • Attacker must have valid user or DHCP client credentials
  • DHCP server must be running on a vulnerable version of Windows Server or Windows 10
Network-based DoS attackAffects network infrastructure (DHCP)Requires valid user credentialsLow exploit probability (EPSS 0.7%)Not currently exploited (not KEV)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict DHCP server network access to only authorized subnets and clients; block unexpected DHCP traffic at network boundaries
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the September 2026 Windows security update (or later) to all Windows DHCP servers
Long-term hardening
0/2
HARDENINGImplement network segmentation to isolate DHCP servers and limit adjacency scope
HARDENINGMonitor DHCP server logs for unexpected crashes or service restarts
API: /api/v1/advisories/08604c7b-8b6a-49b4-a716-b714adb24699

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Denial of Service Vulnerability | CVSS 5.7 - OTPulse