Executive brief
Windows DHCP Server, which handles network address assignment for corporate and home networks, contains an out-of-bounds read vulnerability. An attacker on the network can exploit this flaw to disclose sensitive information from the DHCP server's memory without authentication, potentially revealing configuration details, credentials, or other confidential data.
Technical details
The vulnerability is an out-of-bounds read flaw in the Windows DHCP Server component, allowing information disclosure over a network. The vulnerability requires no authentication and is reachable over the network via DHCP protocol interactions. An attacker can craft malicious DHCP requests or responses that trigger the out-of-bounds read, causing the server to leak memory contents. The attack does not require user interaction or elevated privileges on the attacker's side.
Affected products
- Microsoft Windows DHCP Server <UNKNOWN>
Timeline
- 2026-09-08: disclosed