Junglewise Threat Intelligence

CVE-2026-50370: Microsoft Windows DHCP Server heap buffer overflow

CVE-2026-50370 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 1607, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 10 Version 1809. Vendors: Microsoft.

Executive brief

A critical vulnerability exists in the Windows DHCP Server, a core networking component that automatically assigns IP addresses to devices on a network. An attacker located on the same local network could exploit this flaw to take full control of the server without needing any login credentials. This could lead to a complete service outage, data theft, or a foothold for further attacks within the corporate network.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Windows DHCP Server service due to improper input validation (CWE-20). The flaw can be triggered by an unauthenticated attacker sending specially crafted DHCP packets over an adjacent network (Layer 2). Successful exploitation allows for remote code execution with high privileges on the affected server. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1607 < 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 < 10.0.17763.9020
  • Microsoft Windows Server 2012 / 2012 R2 < 6.2.9200.26226 / < 6.3.9600.23291
  • Microsoft Windows Server 2016 / 2019 < 10.0.14393.9339 / < 10.0.17763.9020

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats