Executive brief
Windows DHCP Server contains an out-of-bounds read vulnerability that allows unauthenticated attackers to cause a denial of service by sending specially crafted network packets. DHCP Server is a core Windows networking service responsible for assigning IP addresses to devices on corporate networks. An attack could disrupt network availability and prevent devices from obtaining proper IP configurations.
Technical details
The vulnerability is an out-of-bounds read in Windows DHCP Server triggered by processing malformed DHCP protocol messages. The flaw allows an unauthenticated attacker on the network to send a specially crafted packet that causes the DHCP Server process to read memory outside its allocated bounds, leading to denial of service (crash). No authentication is required and the attack is network-reachable. The vulnerability does not permit code execution or data exfiltration, only service disruption. A security patch from Microsoft is available.
Affected products
- Microsoft Windows DHCP Server
Timeline
- 2026-09-08: disclosed