Windows DHCP Server Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-77494Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A type confusion vulnerability in Windows DHCP Server allows an unauthenticated attacker to cause a denial of service by sending specially crafted network packets. When exploited, the DHCP service crashes, preventing IP address assignment to network clients. Affected versions include Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 versions 1607 and 1809.
What this means
What could happen
An attacker on the network can crash the Windows DHCP Server by sending specially crafted packets, causing DHCP service to stop and preventing new devices from obtaining IP addresses. This disrupts network connectivity for all machines relying on DHCP, including OT devices.
Who's at risk
Organizations running Windows 10 Version 1809 or older, Windows Server 2016, 2019, 2022, or 2025 as DHCP servers should prioritize this update. This includes water authorities and utilities that use Windows DHCP for IP address management on both IT and OT networks. Any facility relying on DHCP for network connectivity is affected.
How it could be exploited
An attacker sends malformed DHCP packets over the network to a Windows DHCP Server. The type confusion vulnerability in the DHCP service processes the packet incorrectly, causing a crash that disables the DHCP service and blocks IP address assignment across your network.
Prerequisites
- Network access to DHCP server port 67 (UDP)
- DHCP service must be running on the Windows Server
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects network infrastructurecan disrupt DHCP-dependent OT devices
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/7
Do now
0/1WORKAROUNDRestrict network access to DHCP ports (UDP 67/68) to authorized DHCP clients and subnets only
Schedule — requires maintenance window
0/5Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1809 (x64) to Build 10.0.17763.9245 or later
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate DHCP servers from untrusted network segments
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/a9950143-cc5d-45e1-b187-3d29f04cd5acGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.