Windows DHCP Server Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-77886Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in Windows DHCP Server allows an unauthorized attacker on the network to crash the DHCP service by sending a malformed DHCP packet. This denial-of-service condition prevents the server from assigning IP addresses to clients, disrupting network connectivity. Affected versions include Windows 10 (1607, 1809), Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker on your network can send malformed DHCP requests to crash your Windows DHCP server, cutting off IP address assignment to devices and halting normal network operations until the server restarts.
Who's at risk
Any water authority or utility relying on Windows DHCP servers to assign IP addresses to IT infrastructure, field devices, or control system networks. This includes facilities running Windows Server 2016, 2019, 2022, or 2025 in their data center or regional offices, as well as Windows 10 systems configured with DHCP server roles.
How it could be exploited
An attacker with network access to your DHCP server (typically port 67/UDP) sends a specially crafted DHCP packet. The server's DHCP service reads past the end of a memory buffer and crashes, causing the service to stop responding to legitimate IP assignment requests.
Prerequisites
  • Network access to DHCP server on UDP port 67
  • DHCP server must be running on an affected Windows Server or Windows 10 version
remotely exploitableno authentication requiredlow complexityaffects network availability
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/7
Do now
0/1
WORKAROUNDRestrict network access to your DHCP server—firewall rules should allow UDP port 67 only from authorized DHCP clients and deny untrusted sources
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 (including Server Core) to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 (including Server Core) to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 (including Server Core) to Build 10.0.26100.33438 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 (including Server Core) to Build 10.0.14393.9512 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) to Build 10.0.14393.9512 or later
API: /api/v1/advisories/7973e4f7-0feb-41f8-82a7-f9ab02aff064

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Denial of Service Vulnerability | CVSS 7.5 - OTPulse