Executive brief
A security vulnerability exists in the Windows DHCP Server, a service responsible for automatically assigning IP addresses to devices on a network. An attacker with local access to the system could exploit this flaw to view sensitive information that should be protected or cause a service disruption. This could lead to unauthorized data disclosure or impact the availability of network addressing services.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Microsoft Windows DHCP Server component. The flaw is triggered when the service improperly handles memory buffers, allowing a local attacker to read data outside of the intended memory space. While the attack vector is local, the CVSS 3.1 vector indicates no special privileges (PR:N) or user interaction (UI:N) are required once local access is established. Successful exploitation can result in the disclosure of sensitive information from the process memory or a denial-of-service condition (A:H). Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows DHCP Server
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Microsoft published the security update guide.