Junglewise Threat Intelligence

CVE-2026-69845: Microsoft Windows DHCP Server heap-based buffer overflow

CVE-2026-69845 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Executive brief

Windows DHCP Server is a critical network service that assigns IP addresses to devices on corporate networks. A heap-based buffer overflow vulnerability allows an attacker to remotely execute arbitrary code with system-level privileges, potentially compromising an entire network infrastructure and all connected devices.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows DHCP Server component, allowing remote code execution. The vulnerability is exploitable over the network without authentication or user interaction required, making it a worm-like threat. An attacker can send a specially crafted DHCP packet to trigger the overflow and achieve arbitrary code execution in the DHCP Server process context. The vulnerability has been assigned a CVSS score of 9.8 and reported as critical severity.

Affected products

  • Microsoft Windows DHCP Server

Timeline

  • 2026-09-08: disclosed

References

Related threats