Junglewise Threat Intelligence

CVE-2026-69679: Microsoft Windows DHCP Server out-of-bounds read

CVE-2026-69679 · Severity: medium · CVSS 5.7 · Published 2026-09-08

Technologies: Microsoft Windows DHCP Server. Vendors: Microsoft.

Executive brief

Microsoft Windows DHCP Server contains an out-of-bounds read vulnerability that allows an authorized attacker on an adjacent network to cause a denial of service. This affects the core network service responsible for automatically assigning IP addresses to devices, potentially disrupting network connectivity for affected organizations.

Technical details

An out-of-bounds read vulnerability exists in Windows DHCP Server that allows an authorized attacker to trigger a denial-of-service condition. The vulnerability is network-reachable via adjacent network access and requires the attacker to be authorized (e.g., have valid DHCP client credentials or network positioning). By sending a specially crafted DHCP packet, an attacker can cause the DHCP Server to read beyond allocated memory boundaries, resulting in service crash or unavailability. This prevents legitimate clients from obtaining IP addresses via DHCP.

Affected products

  • Microsoft Windows DHCP Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats