Junglewise Threat Intelligence

CVE-2026-69637: Microsoft Windows DHCP Server out-of-bounds read

CVE-2026-69637 · Severity: medium · CVSS 5.7 · Published 2026-09-08

Technologies: Microsoft Windows DHCP Server. Vendors: Microsoft.

Executive brief

Windows DHCP Server is a network service that manages IP address allocation for connected devices. An authorized attacker on the same network segment can trigger an out-of-bounds memory read, causing the DHCP service to crash and preventing devices from obtaining network connectivity.

Technical details

The vulnerability is an out-of-bounds read in the Windows DHCP Server component. The attack requires network adjacency and authorization credentials to trigger the condition. An attacker with adjacent network access and valid credentials can craft a malicious DHCP packet to read past allocated memory boundaries, causing a denial of service by crashing the DHCP service. This prevents legitimate clients from receiving IP address assignments, disrupting network operations.

Affected products

  • Microsoft Windows DHCP Server

Timeline

  • 2026-09-08: disclosed

References

Related threats