Windows DHCP Server Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-77494Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A type confusion vulnerability in Windows DHCP Server allows an unauthenticated attacker to cause a denial of service by sending specially crafted network packets. When exploited, the DHCP service crashes, preventing IP address assignment to network clients. Affected versions include Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 versions 1607 and 1809.

What this means
What could happen
An attacker on the network can crash the Windows DHCP Server by sending specially crafted packets, causing DHCP service to stop and preventing new devices from obtaining IP addresses. This disrupts network connectivity for all machines relying on DHCP, including OT devices.
Who's at risk
Organizations running Windows 10 Version 1809 or older, Windows Server 2016, 2019, 2022, or 2025 as DHCP servers should prioritize this update. This includes water authorities and utilities that use Windows DHCP for IP address management on both IT and OT networks. Any facility relying on DHCP for network connectivity is affected.
How it could be exploited
An attacker sends malformed DHCP packets over the network to a Windows DHCP Server. The type confusion vulnerability in the DHCP service processes the packet incorrectly, causing a crash that disables the DHCP service and blocks IP address assignment across your network.
Prerequisites
  • Network access to DHCP server port 67 (UDP)
  • DHCP service must be running on the Windows Server
  • No authentication required
remotely exploitableno authentication requiredlow complexityaffects network infrastructurecan disrupt DHCP-dependent OT devices
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/7
Do now
0/1
WORKAROUNDRestrict network access to DHCP ports (UDP 67/68) to authorized DHCP clients and subnets only
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1809 (x64) to Build 10.0.17763.9245 or later
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate DHCP servers from untrusted network segments
API: /api/v1/advisories/a9950143-cc5d-45e1-b187-3d29f04cd5ac

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Denial of Service Vulnerability | CVSS 7.5 - OTPulse