Executive brief
A critical vulnerability in the Microsoft Windows DHCP Server allows an unauthorized attacker to tamper with data over the network. The DHCP Server is a vital infrastructure component that automatically assigns IP addresses and network configurations to devices on a corporate network. Successful exploitation could allow an attacker to intercept or modify network traffic, potentially leading to data theft or unauthorized access to sensitive systems.
Technical details
A tampering vulnerability exists in the Microsoft Windows DHCP Server component. The flaw allows an unauthenticated attacker with network access to the DHCP server to perform unauthorized modifications. According to the CVSS vector, the attack is low complexity, requires no elevated privileges, and involves no user interaction. Successful exploitation results in high impact to both confidentiality and integrity, though availability is reportedly not affected. Microsoft has released security updates to address this issue via the MSRC Update Guide.
Affected products
- Microsoft Windows DHCP Server
Timeline
- 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.