Executive brief
The Windows DHCP Client service is responsible for automatically configuring network settings on computers. This vulnerability allows an attacker on the same local network to send specially crafted network traffic that consumes system resources, making the computer unresponsive or forcing it to reboot, disrupting normal business operations.
Technical details
This is an uncontrolled resource consumption vulnerability (CWE-400) in the Windows DHCP Client service. An attacker with network adjacency (same LAN segment) can send malicious DHCP protocol messages that cause excessive resource allocation, leading to denial of service. The attack requires no authentication or user interaction—it can be triggered by sending crafted packets over the local network. An affected system may become unresponsive, lose network connectivity, or require a restart to recover.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-08-11: disclosed