Junglewise Threat Intelligence

CVE-2026-58627: Microsoft Windows DHCP Server denial of service

CVE-2026-58627 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 1607, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012, Microsoft Windows 10 Version 1809, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows DHCP Server could allow an unauthorized attacker to crash the service or make it unavailable to legitimate users. The DHCP server is a critical component that automatically assigns IP addresses to devices on a network; if it fails, new devices cannot connect and existing devices may lose connectivity. This could lead to a significant disruption of network operations across the organization.

Technical details

A denial-of-service vulnerability exists in the Windows DHCP Server due to uncontrolled resource consumption (CWE-400). An unauthenticated attacker can exploit this over the network by sending specially crafted requests that exhaust server resources, leading to service instability or a complete shutdown. The vulnerability is automatable and requires no user interaction. Microsoft has released security updates to address this issue across affected versions of Windows 10 and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226
  • Microsoft Windows Server 2012 R2 6.3.9600.0 to 6.3.9600.23291
  • Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available by Microsoft

References

Related threats