Windows DHCP Client Elevation of Privilege Vulnerability
Plan PatchCVSS 8CVE-2026-69777Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow in the Windows DHCP Client allows an authenticated attacker on an adjacent network segment to elevate privileges and execute arbitrary code. The vulnerability affects Windows 11 versions 25H2, 24H2, and 26H1 across x64 and ARM64 architectures. Microsoft has released fixes in the September 2026 security update with specific build numbers for each version branch.
What this means
What could happen
An attacker on the same network segment as an industrial workstation could exploit a DHCP client vulnerability to gain administrator-level access to Windows systems managing critical equipment like PLCs or SCADA servers. This could allow manipulation of process control logic, sensor data injection, or shutdown of critical operations.
Who's at risk
Organizations running Windows 11 on industrial engineering workstations, SCADA servers, HMI systems, or any networked devices used to manage PLCs, field devices, or critical infrastructure equipment. Affects all versions of Windows 11 with 25H2, 24H2, and 26H1 release branches on both x64 and ARM64 architectures (including tablets and edge computing devices used in OT environments).
How it could be exploited
An attacker crafts a malicious DHCP server response on the same network segment and sends it to a Windows system running a vulnerable DHCP client. If a user with local privileges is logged in, the heap buffer overflow allows the attacker to execute code with elevated (administrator) privileges, bypassing normal access controls.
Prerequisites
- Attacker must have network access to the same local segment (Layer 2/Ethernet) as the target Windows system
- Target must be running a vulnerable DHCP client version
- Requires either an authenticated local user logged in or SYSTEM-level DHCP client process
Remotely exploitable over local network segmentRequires local authentication or elevated user contextHeap buffer overflow has low exploitation complexity once network access is achievedAffects safety-critical systems if Windows systems control PLCs or safety logicLow EPSS score (0.5%) but exploitation is more likely per advisory
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDImplement network access controls (switch port security, DHCP snooping, or MAC filtering) to prevent unauthorized DHCP servers on control network segments
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the September 2026 Windows security update to all Windows 11 systems on the network
Long-term hardening
0/1HARDENINGIsolate engineering workstations and SCADA/control servers to a dedicated network segment separate from office IT networks and guest access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/1016616d-fb2b-444a-addf-3ff9c30de8aeGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.