Executive brief
Windows DHCP Server is a network service that manages IP address allocation for connected devices. An authorized attacker on the same network segment can trigger an out-of-bounds memory read, causing the DHCP service to crash and preventing devices from obtaining network connectivity.
Technical details
The vulnerability is an out-of-bounds read in the Windows DHCP Server component. The attack requires network adjacency and authorization credentials to trigger the condition. An attacker with adjacent network access and valid credentials can craft a malicious DHCP packet to read past allocated memory boundaries, causing a denial of service by crashing the DHCP service. This prevents legitimate clients from receiving IP address assignments, disrupting network operations.
Affected products
- Microsoft Windows DHCP Server
Timeline
- 2026-09-08: disclosed