Executive brief
Windows DHCP Server is a critical network service that assigns IP addresses to devices on corporate networks. A stack-based buffer overflow vulnerability allows an attacker to execute arbitrary code over the network without authentication, potentially compromising the entire network infrastructure and gaining control over IT systems.
Technical details
A stack-based buffer overflow exists in Windows DHCP Server that can be triggered via a malformed network packet. The vulnerability requires no authentication and is exploitable over the network (CVSS vector indicates network-based attack). An attacker can craft a specially designed DHCP packet to overflow a stack buffer, overwrite return addresses, and achieve remote code execution with the privileges of the DHCP Server service. Microsoft has released patches to address this issue.
Affected products
- Microsoft Windows DHCP Server
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory