Junglewise Threat Intelligence

CVE-2026-69412: Microsoft Windows DHCP Server stack-based buffer overflow

CVE-2026-69412 · Severity: high · CVSS 8 · Published 2026-09-08

Technologies: Microsoft Windows DHCP Server. Vendors: Microsoft.

Executive brief

Windows DHCP Server is a network service that assigns IP addresses to devices on a corporate network. A stack-based buffer overflow vulnerability allows an authorized attacker on an adjacent network to execute arbitrary code with elevated privileges, potentially compromising the entire network's IP address management and enabling lateral movement to other systems.

Technical details

A stack-based buffer overflow exists in Microsoft Windows DHCP Server that can be exploited by an authorized attacker over an adjacent network. The vulnerability allows remote code execution without network traversal across the internet. An attacker must have network adjacency (ability to reach the DHCP server on the local network segment) to exploit this issue. Successful exploitation results in arbitrary code execution with the privileges of the DHCP Server service. Patches are available from Microsoft through their Security Update Guide.

Affected products

  • Microsoft Windows DHCP Server

Timeline

  • 2026-09-08: disclosed

References

Related threats