Windows DHCP Server Information Disclosure Vulnerability

MonitorCVSS 5.9CVE-2026-69929Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

Out-of-bounds read vulnerability in Windows DHCP Server allows an unauthenticated attacker to disclose information over the network. An attacker can send specially crafted DHCP requests to trigger an out-of-bounds read, potentially exposing network configuration and system memory contents without authentication.

What this means
What could happen
An attacker could read sensitive information from the DHCP server's memory without authentication, potentially exposing network configuration details, IP assignments, or other cached data. This information could be used to plan further attacks on your network.
Who's at risk
This affects utilities running Windows-based DHCP servers for network address assignment, including municipal IT infrastructure that manages IP allocation for OT devices, building management systems, or office networks. Primarily impacts Windows Server 2016, 2019, 2022, and 2025 deployments.
How it could be exploited
An attacker sends specially crafted DHCP requests to a Windows DHCP server over the network. The server processes the malformed request incorrectly, allowing the attacker to read data beyond the intended buffer boundaries and extract sensitive information from server memory.
Prerequisites
  • Network access to DHCP server on UDP port 67
  • DHCP Server service running on affected Windows system
remotely exploitableno authentication requiredinformation disclosure
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/6
Do now
0/1
WORKAROUNDRestrict network access to DHCP server to only authorized DHCP relay agents and clients; configure firewall rules to block DHCP port 67 from untrusted network segments
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXApply Microsoft 2026-Sep security update to Windows Server 2019 (Build 10.0.17763.9245 or later)
Windows Server 2022
HOTFIXApply Microsoft 2026-Sep security update to Windows Server 2022 (Build 10.0.20348.5622 or later)
Windows Server 2025
HOTFIXApply Microsoft 2026-Sep security update to Windows Server 2025 (Build 10.0.26100.33438 or later)
Windows Server 2016
HOTFIXApply Microsoft 2026-Sep security update to Windows 10 Version 1607 and Windows Server 2016 (Build 10.0.14393.9512 or later)
All products
HOTFIXApply Microsoft 2026-Sep security update to Windows 10 Version 1809 (Build 10.0.17763.9245 or later)
API: /api/v1/advisories/a33a9843-2512-4df8-bcc9-16626f1af2d1

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.