Executive brief
Windows DHCP Server is a critical network service that assigns IP addresses to computers on corporate networks. A heap buffer overflow vulnerability allows an authorized network attacker to execute arbitrary code with system privileges, potentially compromising the entire network infrastructure and all connected devices.
Technical details
This vulnerability is a heap-based buffer overflow in the Windows DHCP Server component. The flaw allows an authorized attacker with network access to trigger memory corruption through crafted network packets, enabling remote code execution with system privileges. The vulnerability requires the attacker to have network connectivity to the DHCP server and authentication/authorization to interact with the service. A successful exploit could lead to complete system compromise and lateral movement within the network. Microsoft has released patches to address this issue.
Affected products
- Microsoft Windows DHCP Server <UNKNOWN>
Timeline
- 2026-09-08: disclosed