Windows DHCP Server Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-77499Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A type confusion vulnerability in Windows DHCP Server allows an unauthenticated attacker on the network to cause a denial of service by sending malformed DHCP requests. The vulnerability affects Windows 10 (versions 1607 and 1809), Windows Server 2016, 2019, 2022, and 2025. The vulnerability results in DHCP service crash and unavailability.

What this means
What could happen
An attacker on the network can crash your Windows DHCP server, preventing all devices from obtaining IP addresses and potentially halting network operations and water/power delivery systems.
Who's at risk
Water and electric utilities using Windows DHCP servers (Windows Server 2016, 2019, 2022, 2025, or Windows 10) to assign IP addresses to networked equipment including SCADA systems, RTUs, and field devices. Any organization where DHCP outage would disrupt network operations.
How it could be exploited
An attacker sends a specially crafted DHCP request to your DHCP server over the network. The malformed request triggers a type confusion bug in the DHCP service, causing the service to crash and stop responding to legitimate DHCP clients.
Prerequisites
  • Network access to the DHCP server on port 67/UDP (DHCP service port)
  • No credentials required
remotely exploitableno authentication requiredlow complexityaffects network infrastructure critical to OT operations
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict inbound DHCP traffic (port 67/UDP) to only known legitimate subnets and DHCP relay agents
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Sep Windows security update to all Windows DHCP servers
Long-term hardening
0/1
HARDENINGSegment DHCP servers on a dedicated network or VLAN to limit access from untrusted networks
API: /api/v1/advisories/c8963cbe-3ebf-4909-9e01-a2b04f74af52

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.