Junglewise Threat Intelligence

CVE-2026-56159: Microsoft Windows DHCP Server heap overflow remote code execution

CVE-2026-56159 · Severity: critical · CVSS 9.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 1607, Microsoft Windows 10 Version 1809, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

A critical vulnerability has been identified in the Windows DHCP Server, a core service that automatically assigns IP addresses to devices on a network. An unauthorized attacker could exploit this flaw over the network to gain full control of the server without any user interaction. This could lead to a complete service outage, data theft, or a foothold for further attacks within the corporate network.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Microsoft Windows DHCP Server service. The flaw is triggered when the service improperly handles specially crafted DHCP packets sent over the network. An unauthenticated, remote attacker can exploit this by sending malicious requests to a vulnerable server, leading to arbitrary code execution in the context of the service. The vulnerability is highly automatable and requires no user interaction. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9338
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9019
  • Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26225
  • Microsoft Windows Server 2012 R2 6.3.9600.0 to 6.3.9600.23290
  • Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9338
  • Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9019

Timeline

  • 2026-07-14: advisory: Microsoft published the security advisory and NVD entry.
  • 2026-07-14: patched: Security updates released by Microsoft.

References

Related threats