Executive brief
A vulnerability in the Windows DHCP Client allows an unauthorized attacker to gain elevated privileges over a network. The DHCP Client is a standard component that allows Windows computers to automatically receive network configuration settings. If exploited, an attacker could potentially access sensitive information or gain higher-level control over the affected system without needing physical access or user interaction.
Technical details
An integer underflow (CWE-191) exists in the Windows DHCP Client component. The vulnerability is triggered when the client processes specially crafted DHCP packets, leading to a wrap or wraparound condition. An unauthenticated attacker can exploit this over the network without any user interaction to achieve an elevation of privilege. While the CVSS vector indicates high confidentiality impact, the primary risk is the unauthorized escalation of rights on the target system. Microsoft has released security updates to address this issue across various versions of Windows 10 and Windows Server.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows Server 2012 / 2012 R2 6.2.9200.0 to 6.2.9200.26226 / 6.3.9600.0 to 6.3.9600.23291
- Microsoft Windows Server 2016 / 2019 10.0.14393.0 to 10.0.14393.9339 / 10.0.17763.0 to 10.0.17763.9020
Timeline
- 2026-07-14: disclosed: Initial publication of the CVE record and Microsoft advisory.
- 2026-07-14: patched: Security updates released by Microsoft.