Executive brief
Windows DHCP Client is a network service used by computers to automatically obtain IP addresses from a DHCP server. A memory leak vulnerability in this component allows an attacker on an adjacent network (such as the same Wi-Fi network) to repeatedly trigger the leak, exhausting system memory and causing the affected computer to slow down or crash, denying service to legitimate users.
Technical details
The vulnerability is a memory leak (use-after-free or failure to release memory) in the Windows DHCP Client. An attacker on an adjacent network can craft malicious DHCP responses or packets that trigger the memory leak repeatedly without authentication. By exhausting available memory over time, the attacker can degrade system performance or force a denial of service. A patch is available from Microsoft.
Affected products
- Microsoft Windows multiple versions (unspecified)
Timeline
- 2026-09-08: disclosed