Windows DHCP Server Remote Code Execution Vulnerability
Plan PatchCVSS 8CVE-2026-69847Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow vulnerability exists in Windows DHCP Server that allows an attacker with network access to execute arbitrary code on the DHCP server with SYSTEM privileges. The vulnerability is triggered by a malformed DHCP request sent over the network.
What this means
What could happen
An attacker with network access to your DHCP server could overflow a memory buffer to run arbitrary code on that server, potentially disrupting network connectivity for all devices that depend on DHCP for IP address assignment or extracting sensitive configuration data.
Who's at risk
IT managers operating Windows-based DHCP servers for network infrastructure, including those in utilities, manufacturing, and facilities management who rely on Windows Server 2016, 2019, 2022, 2025, or Windows 10/11 systems to assign IP addresses to operational technology (OT) devices. This affects any organization using Windows DHCP Server in networked environments.
How it could be exploited
An attacker on the same network segment as your DHCP server (or with routing access to it) sends a malformed DHCP request that triggers a heap-based buffer overflow in the Windows DHCP Server service. This allows the attacker to execute arbitrary code with SYSTEM privileges on the server.
Prerequisites
- Network access to DHCP server port 67/UDP (DHCP)
- Attacker must be on the same network segment or have layer-2/3 connectivity to the DHCP server
- DHCP Server service must be running
remotely exploitablelow complexityhigh CVSS score (8.0)affects network infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to DHCP server port 67/UDP to only authorized DHCP clients and management interfaces using firewall rules or network segmentation
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the September 2026 Windows security update to all affected Windows and Windows Server systems running DHCP Server
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate DHCP servers from untrusted network segments
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ec2c9b29-ed1b-474c-babc-ca0f2ad15b43Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.