Windows DHCP Client Elevation of Privilege Vulnerability

Plan PatchCVSS 8CVE-2026-69777Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow in the Windows DHCP Client allows an authenticated attacker on an adjacent network segment to elevate privileges and execute arbitrary code. The vulnerability affects Windows 11 versions 25H2, 24H2, and 26H1 across x64 and ARM64 architectures. Microsoft has released fixes in the September 2026 security update with specific build numbers for each version branch.

What this means
What could happen
An attacker on the same network segment as an industrial workstation could exploit a DHCP client vulnerability to gain administrator-level access to Windows systems managing critical equipment like PLCs or SCADA servers. This could allow manipulation of process control logic, sensor data injection, or shutdown of critical operations.
Who's at risk
Organizations running Windows 11 on industrial engineering workstations, SCADA servers, HMI systems, or any networked devices used to manage PLCs, field devices, or critical infrastructure equipment. Affects all versions of Windows 11 with 25H2, 24H2, and 26H1 release branches on both x64 and ARM64 architectures (including tablets and edge computing devices used in OT environments).
How it could be exploited
An attacker crafts a malicious DHCP server response on the same network segment and sends it to a Windows system running a vulnerable DHCP client. If a user with local privileges is logged in, the heap buffer overflow allows the attacker to execute code with elevated (administrator) privileges, bypassing normal access controls.
Prerequisites
  • Attacker must have network access to the same local segment (Layer 2/Ethernet) as the target Windows system
  • Target must be running a vulnerable DHCP client version
  • Requires either an authenticated local user logged in or SYSTEM-level DHCP client process
Remotely exploitable over local network segmentRequires local authentication or elevated user contextHeap buffer overflow has low exploitation complexity once network access is achievedAffects safety-critical systems if Windows systems control PLCs or safety logicLow EPSS score (0.5%) but exploitation is more likely per advisory
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2954
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2954
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDImplement network access controls (switch port security, DHCP snooping, or MAC filtering) to prevent unauthorized DHCP servers on control network segments
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the September 2026 Windows security update to all Windows 11 systems on the network
Long-term hardening
0/1
HARDENINGIsolate engineering workstations and SCADA/control servers to a dedicated network segment separate from office IT networks and guest access
API: /api/v1/advisories/1016616d-fb2b-444a-addf-3ff9c30de8ae

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Client Elevation of Privilege Vulnerability | CVSS 8 - OTPulse