Junglewise Threat Intelligence

CVE-2026-69547: Microsoft Windows DHCP Server heap buffer overflow

CVE-2026-69547 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Windows DHCP Server. Vendors: Microsoft.

Executive brief

Windows DHCP Server is a critical network service that assigns IP addresses to computers on corporate networks. A heap buffer overflow vulnerability allows an authorized network attacker to execute arbitrary code with system privileges, potentially compromising the entire network infrastructure and all connected devices.

Technical details

This vulnerability is a heap-based buffer overflow in the Windows DHCP Server component. The flaw allows an authorized attacker with network access to trigger memory corruption through crafted network packets, enabling remote code execution with system privileges. The vulnerability requires the attacker to have network connectivity to the DHCP server and authentication/authorization to interact with the service. A successful exploit could lead to complete system compromise and lateral movement within the network. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Windows DHCP Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats