Junglewise Threat Intelligence

CVE-2026-50518: Microsoft Windows DHCP Server heap overflow remote code execution

CVE-2026-50518 · Severity: critical · CVSS 9.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 1607, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012, Microsoft Windows 10 Version 1809, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

A critical vulnerability has been identified in the Windows DHCP Server, a core service that automatically assigns IP addresses to devices on a network. An attacker could exploit this flaw over the network without any user interaction or special permissions to take full control of the server. This could lead to a complete service outage, theft of sensitive data, or a foothold for further attacks within the corporate network.

Technical details

This vulnerability is a heap-based buffer overflow (CWE-122) residing in the Windows DHCP Server service. The flaw can be triggered by a remote, unauthenticated attacker sending specially crafted DHCP packets over the network. Successful exploitation allows for remote code execution (RCE) in the context of the service, which typically runs with high privileges. Microsoft has released security updates to address this issue across affected versions of Windows 10 and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226
  • Microsoft Windows Server 2012 R2 6.3.9600.0 to 6.3.9600.23291
  • Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide

References

Related threats