Junglewise Threat Intelligence

CVE-2026-69415: Microsoft Windows DHCP Server privilege escalation over network

CVE-2026-69415 · Severity: medium · CVSS 6.8 · Published 2026-09-08

Technologies: Microsoft Windows DHCP Server. Vendors: Microsoft.

Executive brief

Windows DHCP Server is a critical network service that assigns IP addresses to devices on corporate networks. A vulnerability in authentication logic allows an authorized attacker to escalate their privileges across the network, potentially gaining higher-level access to manage DHCP infrastructure and affect network operations.

Technical details

The vulnerability is a missing authentication control in a critical function within Windows DHCP Server. It permits an authorized network attacker to escalate privileges without proper validation. The attack is network-accessible and requires existing authenticated access. An attacker can exploit this to elevate their privilege level and potentially control DHCP operations or access restricted administrative functions. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows DHCP Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats