Windows DHCP Server Remote Code Execution Vulnerability
MonitorCVSS 6.4CVE-2026-69878Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredHigh
ComplexityHigh
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows DHCP Server service. An authorized administrator or DHCP administrator with local or remote access to the server can trigger the overflow to execute code with system privileges. Affects Windows 10 versions 1607 and 1809, and Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
A Windows DHCP Server with this vulnerability could allow an authorized user with administrative credentials to execute code locally with high privileges, potentially disrupting network services or modifying system configuration.
Who's at risk
Water authorities and municipal utilities running Windows-based DHCP servers for network management should assess whether they have affected Windows Server 2016, 2019, 2022, or 2025 systems serving as DHCP servers. This affects both standard and Server Core installations.
How it could be exploited
An attacker with administrator or DHCP administrative credentials on the DHCP server system could trigger a heap-based buffer overflow in the DHCP service to execute arbitrary code with system privileges. This requires local or remote administrative access to the server itself.
Prerequisites
- Administrator or DHCP administrative credentials on the affected Windows server
- Local or remote access to the DHCP server system
- High privileges (administrative level) required to trigger
Local privilege escalationRequires high privileges (administrator credentials)Low exploit probability (0.3% EPSS)Not actively exploited
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/8
Schedule — requires maintenance window
0/7Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXUpdate Windows Server 2016 systems to Build 10.0.14393.9512 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 systems to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 systems to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 systems to Build 10.0.26100.33438 or later
All products
HOTFIXApply Microsoft September 2026 security update to patch the DHCP Server vulnerability
HOTFIXUpdate Windows 10 Version 1607 systems to Build 10.0.14393.9512 or later
HOTFIXUpdate Windows 10 Version 1809 systems to Build 10.0.17763.9245 or later
Long-term hardening
0/1HARDENINGRestrict DHCP administrative credentials to only necessary personnel and monitor administrative activity on DHCP servers
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/2f8c6f92-6c4a-4283-855a-73432ae5a967Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.