Junglewise Threat Intelligence

CVE-2026-50685: Microsoft Windows DHCP Server double free remote code execution

CVE-2026-50685 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 1607, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012, Microsoft Windows Server 2022, Microsoft Windows 10 Version 1809, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows DHCP Server, a core service that automatically assigns IP addresses to devices on a network. An authorized user on the network could exploit this flaw to execute malicious code on the server. This could lead to a complete takeover of the server, potentially disrupting network operations or allowing access to sensitive data.

Technical details

A double free vulnerability (CWE-415) exists in the Microsoft Windows DHCP Server service. The flaw is triggered when the service incorrectly handles memory allocation during the processing of specific network requests. An attacker with low-level authenticated access to the network can exploit this by sending specially crafted packets to the DHCP server. Successful exploitation requires the attacker to win a race condition (High Attack Complexity) but can result in remote code execution with the privileges of the DHCP service. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226
  • Microsoft Windows Server 2012 R2 6.3.9600.0 to 6.3.9600.23291
  • Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.2582

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates released by Microsoft

References

Related threats