Junglewise Threat Intelligence

CVE-2026-44815: Microsoft Windows stack overflow in DHCP Client

CVE-2026-44815 · Severity: critical · CVSS 9.8 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A critical vulnerability exists in the Windows DHCP Client, a core component that allows computers to automatically receive network configuration settings. An attacker could exploit this flaw over a network to gain full control of a target system without any user interaction. This poses a severe risk to data confidentiality and could lead to significant operational disruptions or ransomware deployment.

Technical details

A stack-based buffer overflow (CWE-121) exists in the Microsoft Windows DHCP Client. The vulnerability is triggered when the client processes specially crafted DHCP responses sent over the network. An unauthenticated attacker on the same network segment (or potentially via a DHCP relay) can exploit this to achieve remote code execution (RCE) with high privileges. No user interaction or prior authentication is required for a successful attack. Microsoft has released security updates to address this issue; administrators should apply these patches immediately to mitigate the risk of full system compromise.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References