Windows DHCP Server Remote Code Execution Vulnerability
MonitorCVSS 6.4CVE-2026-77887Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredHigh
ComplexityHigh
User InteractionNone needed
Summary
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally on affected Windows 10 and Windows Server systems.
What this means
What could happen
An attacker with administrative privileges on a DHCP server could run arbitrary code locally, potentially disrupting DHCP services that assign IP addresses to network devices including OT equipment.
Who's at risk
Water utilities and municipalities running Windows DHCP servers (Windows Server 2016, 2019, 2022, 2025) should prioritize patching if they use these servers to assign addresses to network infrastructure, control systems, or OT devices. Windows 10 systems running DHCP server role are less likely in production OT environments but should still be updated if present.
How it could be exploited
An attacker with administrative credentials on a Windows DHCP server could trigger an out-of-bounds read condition in the DHCP service to execute arbitrary code with local system privileges. This would require local or administrative-level network access to the DHCP server itself.
Prerequisites
- Administrative or equivalent elevated privileges on the Windows DHCP server
- Local access to the DHCP server or ability to send specially crafted DHCP packets from the local network
Requires high privileges to exploitHigh complexity attackLow exploit probability (0.2% EPSS)Could affect DHCP-dependent OT devices if server is compromised
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's 2026-Sep security update to all affected Windows Server and Windows 10 systems running DHCP server role
Long-term hardening
0/1HARDENINGRestrict administrative access to DHCP servers; remove unnecessary admin accounts and use principle of least privilege
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/8d938077-8de8-473e-85a1-c6f0034899c2Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.