Windows DHCP Server Remote Code Execution Vulnerability

Plan PatchCVSS 9.8CVE-2026-69845Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over the network. The vulnerability is triggered when a specially crafted DHCP packet is sent to an affected DHCP server. Affects Windows 10 Version 1607 and 1809, Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker on the network could send a specially crafted DHCP request that causes the DHCP server to crash or run arbitrary code with system privileges, disrupting IP address assignment for devices on your network and potentially gaining control of the server itself.
Who's at risk
Mid-size utilities and municipalities running Windows-based DHCP servers for network infrastructure, including domain controllers and dedicated DHCP appliances. Affects Windows Server 2016, 2019, 2022, 2025, and Windows 10 deployments used in administrative/corporate networks.
How it could be exploited
An attacker sends a malicious DHCP packet to your DHCP server over the network. The packet triggers a heap buffer overflow in the Windows DHCP Server process, allowing the attacker to execute arbitrary code with the privileges of the DHCP service (typically system-level).
Prerequisites
  • Network access to DHCP port 67/UDP
  • Target must be running Windows DHCP Server (typically a domain controller or dedicated DHCP server)
  • No authentication required
remotely exploitableno authentication requiredlow complexitycritical CVSS 9.8affects network infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the September 2026 Microsoft security update to all affected Windows servers (Windows Server 2016, 2019, 2022, 2025 and Windows 10 Version 1607, 1809)
API: /api/v1/advisories/855b636f-9ba8-4e27-af72-35e7ae7a3d1d

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Remote Code Execution Vulnerability | CVSS 9.8 - OTPulse