Windows DHCP Server Remote Code Execution Vulnerability

Plan PatchCVSS 8CVE-2026-69876Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Use-after-free memory corruption in Windows DHCP Server allows an authorized attacker on an adjacent network segment to execute arbitrary code with DHCP service privileges. The vulnerability is in how the DHCP server handles certain requests, causing memory management errors that can be leveraged for code execution. Exploitation requires local network access and valid user credentials but does not require administrator privileges.

What this means
What could happen
An attacker on your local network segment with valid credentials could execute arbitrary code on your Windows DHCP server, potentially disrupting network address assignment for critical control system devices or altering network configurations.
Who's at risk
Windows Server administrators and network operators responsible for DHCP infrastructure in industrial facilities. Specifically affects any Windows Server 2016, 2019, 2022, or 2025 running DHCP services, and Windows 10 systems configured as DHCP servers. This is relevant if your water authority or utility operates DHCP for device provisioning or network management.
How it could be exploited
An attacker with credentials on the adjacent network sends a specially crafted packet to the DHCP server, triggering a use-after-free memory corruption that allows code execution with DHCP service privileges. This requires network access to the DHCP service port (typically UDP 67/68) and valid user credentials on that network segment.
Prerequisites
  • Network access to DHCP server on adjacent network segment (AV:A)
  • Valid user credentials to access the local network
  • DHCP service running on target Windows server
adjacent network access requiredvalid credentials requiredlow exploitation complexityhigh impact (code execution on infrastructure service)affects network services critical to device communication
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to DHCP ports (UDP 67/68) to only authorized management and client subnets using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Windows September 2026 security updates to affected Windows Server and Windows 10 systems
Long-term hardening
0/1
HARDENINGSegment your DHCP servers on isolated network zones separate from process control network traffic
API: /api/v1/advisories/9361919d-b4a0-4ae6-8075-5f694429f4e0

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Remote Code Execution Vulnerability | CVSS 8 - OTPulse