Windows DHCP Client Denial of Service Vulnerability

MonitorCVSS 6.5CVE-2026-69781Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A memory leak in the Windows DHCP Client allows an attacker on the same local network segment to cause a denial of service by sending specially crafted DHCP responses. The vulnerability results from improper memory management in the DHCP client, where memory is not released after its effective lifetime. Exploitation is assessed as unlikely, and the issue is addressed in the 2026-Sep security update.

What this means
What could happen
An attacker on the same local network segment could trigger a memory leak in the Windows DHCP client, potentially causing the device to become unresponsive or require a restart, disrupting network connectivity for that host.
Who's at risk
IT managers and OT operators managing Windows Server 2025 or Windows 11 systems that function as engineering workstations, HMI (Human Machine Interface) hosts, or data historian servers in utility environments. Any Windows-based compute platform with DHCP client enabled on a network segment accessible to untrusted devices.
How it could be exploited
An attacker sends specially crafted DHCP responses to a Windows device on the same network segment. The DHCP client processes the malformed response, fails to properly release allocated memory, and over multiple requests the accumulated leak exhausts available memory, causing the device to become unresponsive.
Prerequisites
  • Attacker must be on the same local network segment (adjacent network access)
  • No authentication required
  • Target device must have DHCP client enabled and configured to accept DHCP responses
remotely exploitable (via adjacent network)no authentication requiredlow complexityaffects availability (denial of service)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9445
Windows Server 2025All versionsBuild 10.0.26100.33438
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2954
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2954
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXApply the 2026-Sep security update to all Windows Server 2025, Windows 11 24H2, 25H2, and 26H1 systems
API: /api/v1/advisories/d7f19c4d-8310-4211-8c81-85389656c74a

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.