Junglewise Threat Intelligence

CVE-2026-69620: Microsoft Windows DHCP Server stack-based buffer overflow

CVE-2026-69620 · Severity: high · CVSS 8.1 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows DHCP Server is a critical network service that assigns IP addresses to devices on a corporate network. A stack-based buffer overflow vulnerability allows an attacker to remotely execute code on affected servers over the network without authentication, potentially compromising the entire network infrastructure and enabling lateral movement to other systems.

Technical details

A stack-based buffer overflow exists in Microsoft Windows DHCP Server that can be exploited by sending specially crafted DHCP protocol messages over the network. The vulnerability requires no authentication and can be triggered remotely by any attacker with network access to the DHCP service. Successful exploitation allows arbitrary code execution with the privileges of the DHCP Server service, which typically runs with high system privileges. This is a critical vulnerability in a core network infrastructure component that is difficult to isolate.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats