Windows DHCP Server Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-77498Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. The vulnerability can be exploited remotely without authentication or user interaction.
What this means
What could happen
An attacker on the network could crash the DHCP server, disrupting IP address assignment for all connected devices and potentially halting network communication across your facility.
Who's at risk
Windows Server administrators running DHCP services, particularly those in water utilities, electric utilities, and other critical infrastructure that rely on centralized DHCP for device network configuration. Affects Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 systems configured as DHCP servers.
How it could be exploited
An attacker sends a specially crafted DHCP request to the DHCP server on port 67/UDP. The malformed packet triggers an out-of-bounds read, causing the DHCP service to crash and stop responding to legitimate IP assignment requests.
Prerequisites
- Network access to port 67/UDP (DHCP)
- Windows DHCP Server service must be active and exposed to the network
remotely exploitableno authentication requiredlow complexityhigh availability impact on network operationsaffects infrastructure services
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to port 67/UDP to only authorized DHCP clients using firewall rules or network segmentation
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the September 2026 security update to patch the DHCP Server vulnerability
Long-term hardening
0/1HARDENINGSegregate the DHCP server to a dedicated network segment not directly accessible from untrusted networks
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/c798560c-d1f2-46e6-91e7-9095b770db18Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.