Junglewise Threat Intelligence

CVE-2026-69847: Microsoft Windows DHCP Server heap-based buffer overflow

CVE-2026-69847 · Severity: high · CVSS 8 · Published 2026-09-08

Executive brief

Windows DHCP Server is a core networking component that automatically assigns IP addresses to devices on a corporate network. A heap-based buffer overflow vulnerability allows an authorized attacker on an adjacent network segment to execute arbitrary code on the affected server, potentially compromising network infrastructure and gaining control over systems connected to it.

Technical details

The vulnerability is a heap-based buffer overflow in the Windows DHCP Server component, triggered by processing specially crafted DHCP protocol messages. The attack requires the attacker to be positioned on an adjacent network segment with access to the target DHCP server. An authorized attacker can exploit this to achieve remote code execution in the context of the DHCP Server service. The vulnerability is not currently known to be exploited in the wild, but a patch should be applied promptly given the network-adjacent attack vector and code execution impact.

Affected products

  • Microsoft Windows DHCP Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats