Windows DHCP Server Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-70065Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A memory leak in Windows DHCP Server allows an unauthenticated attacker to cause denial of service by sending specially crafted network packets. The DHCP Server fails to release memory properly, leading to memory exhaustion and eventual service crash. This affects Windows 10 Version 1607 and 1809, Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker on your network could send specially crafted packets to the Windows DHCP server, causing it to leak memory and eventually crash, disrupting DHCP service and preventing devices from obtaining IP addresses.
Who's at risk
Water authorities and electric utilities running Windows Server 2016, 2019, 2022, or 2025 as DHCP servers should care. DHCP is critical infrastructure in these environments—if your DHCP server crashes, connected devices (PLCs, RTUs, control workstations, field devices) cannot obtain or renew network connectivity, causing operational disruption.
How it could be exploited
An attacker with network access to port 67 (DHCP) sends malformed DHCP packets to the server. The Windows DHCP Server fails to properly release memory after processing these packets, causing memory exhaustion over time until the service stops responding to DHCP requests.
Prerequisites
  • Network access to port 67 (DHCP) on the affected server
  • No authentication required
remotely exploitableno authentication requiredlow complexityaffects network infrastructure availability
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/5
Do now
0/1
WORKAROUNDRestrict network access to DHCP port 67 to only authorized DHCP clients and management networks using firewall rules
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXApply Microsoft's 2026-Sep security update to Windows Server 2019 (Build 10.0.17763.9245) or later
Windows Server 2022
HOTFIXApply Microsoft's 2026-Sep security update to Windows Server 2022 (Build 10.0.20348.5622) or later
Windows Server 2025
HOTFIXApply Microsoft's 2026-Sep security update to Windows Server 2025 (Build 10.0.26100.33438) or later
Long-term hardening
0/1
HARDENINGSegment DHCP servers onto isolated networks to limit exposure to untrusted sources
API: /api/v1/advisories/d23035fe-1b74-47bd-aaf1-206e057419fb

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Denial of Service Vulnerability | CVSS 7.5 - OTPulse