Windows DHCP Server Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-77501Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read vulnerability in Windows DHCP Server allows an unauthorized attacker to deny service over the network. The vulnerability exists in DHCP request processing and can be exploited by sending specially crafted packets to cause the DHCP service to crash, preventing normal IP address assignment operations.
What this means
What could happen
An attacker could send malformed DHCP requests over the network to crash or disable a Windows DHCP server, preventing it from assigning IP addresses to devices and disrupting network connectivity across your infrastructure.
Who's at risk
Windows Server administrators who operate DHCP servers (Windows Server 2016, 2019, 2022, 2025) and any Windows 10 systems configured as DHCP servers should prioritize patching. This affects IT infrastructure in any organization using these platforms for network address assignment, including utilities, municipalities, and enterprises that depend on reliable IP allocation for control systems and workstations.
How it could be exploited
An attacker on the network sends a specially crafted DHCP request packet to port 67 of a Windows DHCP server. The server's DHCP service fails to properly validate the request, causing an out-of-bounds memory read that crashes the service. No credentials or authentication are required; the attacker only needs network access to reach the DHCP server.
Prerequisites
- Network access to UDP port 67 (DHCP) on the Windows DHCP server
- Server must be running an affected Windows version with the DHCP Server role or service enabled
remotely exploitableno authentication requiredlow complexityhigh availability impact
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Do now
0/1WORKAROUNDRestrict DHCP server access by configuring firewall rules to allow DHCP traffic (UDP port 67) only from authorized network segments and subnets
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Sep security update to all affected Windows Server and Windows 10 systems running the DHCP Server role
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/a853de4e-a983-4f09-97f6-dd88f06dfd89Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.