Junglewise Threat Intelligence

CVE-2026-48564: Microsoft Windows DHCP Server heap buffer overflow

CVE-2026-48564 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 1607, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012, Microsoft Windows 10 Version 1809, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows DHCP Server, a core service that automatically assigns IP addresses to devices on a network. An authorized user on the network could exploit this flaw to run malicious code on the server. This could lead to a full system takeover, allowing an attacker to disrupt network operations or access sensitive data.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Microsoft Windows DHCP Server service. The flaw is triggered when the service improperly handles specially crafted network packets. An attacker with low-privileged network credentials can exploit this vulnerability remotely without user interaction to achieve arbitrary code execution in the context of the service. Microsoft has released security updates to address this issue across affected versions of Windows 10 and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26132
  • Microsoft Windows Server 2012 R2 6.3.9600.0 to 6.3.9600.23228
  • Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD
  • 2026-07-14: advisory

References

Related threats