Windows DHCP Server Remote Code Execution Vulnerability

Plan PatchCVSS 9.8CVE-2026-72979Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Use after free vulnerability in Windows DHCP Server allows an unauthorized attacker to execute code over the network. The vulnerability affects Windows Server 2016, 2019, 2022, 2025 and Windows 10 versions 1607 and 1809. Microsoft has released security updates for all affected versions. Exploitation is assessed as less likely, but patches should be applied when maintenance windows permit.

What this means
What could happen
An attacker on your network could send specially crafted DHCP requests to a Windows DHCP server and execute code with system privileges, potentially taking control of the DHCP service and disrupting network address assignment for all connected devices.
Who's at risk
Water utilities and municipal electric utilities running Windows Server as DHCP servers in their IT infrastructure. Any organization using Windows Server 2016, 2019, 2022, 2025, or Windows 10 1607 and 1809 for DHCP services is affected.
How it could be exploited
An attacker with network access to your DHCP server sends a malicious DHCP request packet. The use-after-free vulnerability in the DHCP Server service is triggered, allowing the attacker to execute arbitrary code on the server without needing valid credentials or user interaction.
Prerequisites
  • Network access to DHCP server on port 67/UDP
  • DHCP Server service running on Windows Server 2016, 2019, 2022, 2025, or Windows 10
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.8)
Exploitability
Unlikely to be exploited — EPSS score 1.0%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/7
Do now
0/1
WORKAROUNDRestrict DHCP server network access: limit UDP port 67 inbound to only authorized DHCP clients and subnets using firewall rules or network segmentation
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 and Server Core to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 and Server Core to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 and Server Core to Build 10.0.26100.33438 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 and Server Core to Build 10.0.14393.9512 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) to Build 10.0.14393.9512 or later
API: /api/v1/advisories/43235a3f-7a0b-478a-8717-f52f085e3370

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Remote Code Execution Vulnerability | CVSS 9.8 - OTPulse