Executive brief
A security vulnerability exists in the Microsoft Windows DHCP Server, a service responsible for automatically assigning IP addresses to devices on a network. An authorized user with low-level access to the system could exploit this flaw to view sensitive information that should normally be protected. While this does not allow an attacker to take over the server or disrupt service, it could lead to the exposure of confidential data that could be used in further attacks.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists within the Microsoft Windows DHCP Server component. The flaw is triggered when the service improperly handles memory buffers, allowing a local attacker with low privileges (PR:L) to read data outside of the intended memory space. This vulnerability does not require user interaction and has a low attack complexity. Successful exploitation results in a high impact on confidentiality, as the attacker can disclose sensitive information from the server's memory, though it does not directly impact system integrity or availability. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Windows DHCP Server
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory