Executive brief
Windows DHCP Server stores certain passwords in a recoverable (plaintext or weakly encrypted) format. An attacker with authorized network access can retrieve these credentials, potentially leading to unauthorized access to network resources and systems that depend on DHCP configuration credentials.
Technical details
Windows DHCP Server stores authentication credentials in a recoverable format rather than using strong cryptographic hashing. This allows an attacker with authorized access (or network connectivity to the DHCP server) to extract stored passwords through the server's configuration or memory. The vulnerability requires the attacker to be authenticated or have network reachability to the DHCP service. Successful exploitation enables credential disclosure, which can be used to gain unauthorized access to related services or network infrastructure. A security update has been released by Microsoft to address this issue.
Affected products
- Microsoft Windows DHCP Server <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory