Junglewise Threat Intelligence

CVE-2026-69266: Microsoft Windows DHCP Server integer overflow

CVE-2026-69266 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Windows DHCP Server. Vendors: Microsoft.

Executive brief

Windows DHCP Server is a networking service that automatically assigns IP addresses to devices on a corporate network. An integer overflow vulnerability allows an attacker to remotely send a specially crafted network packet that causes the service to crash or execute malicious code, potentially compromising server availability and enabling lateral movement within the network.

Technical details

An integer overflow or wraparound vulnerability exists in Windows DHCP Server's packet handling logic. The vulnerability is triggered by a network-reachable attacker sending a malformed DHCP protocol message that causes an integer calculation to overflow. No authentication is required; exploitation occurs at the network boundary. A successful exploit results in remote code execution with DHCP Server privileges, typically SYSTEM-level access on Windows servers. Patches are available from Microsoft via the Security Update Guide.

Affected products

  • Microsoft Windows DHCP Server

Timeline

  • 2026-09-08: disclosed

References

Related threats