Windows DHCP Server Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-77502Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read flaw in Windows DHCP Server allows an unauthenticated remote attacker to send malformed DHCP packets that cause the DHCP service to crash, resulting in denial of service. Affected versions include Windows Server 2016, 2019, 2022, 2025 and Windows 10 versions 1607 and 1809.
What this means
What could happen
An attacker on the network can crash the DHCP server by sending malformed network packets, preventing new devices and existing clients from obtaining or renewing IP addresses. This disrupts all network operations dependent on the DHCP service.
Who's at risk
Water utilities, electric utilities, and other municipal agencies running Windows Server 2016, 2019, 2022, or 2025 as a DHCP server should prioritize this patch. Windows 10 clients functioning as DHCP servers are also affected. The DHCP service is critical for IP address management across all network devices, including OT equipment, switches, and management systems.
How it could be exploited
An attacker sends specially crafted DHCP requests to the Windows DHCP Server over the network (port 67/68). The out-of-bounds read flaw in the DHCP service causes the service to crash, triggering a denial of service condition. No authentication is required.
Prerequisites
- Network access to DHCP server on port 67 or 68
- DHCP Server role installed and active on the target Windows system
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects network infrastructure services
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-September security update to your Windows Server and Windows 10 systems running the DHCP Server role
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/af7efb3c-f952-455a-8999-749e383ebbe0Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.