Executive brief
Windows DHCP Server is a network service that assigns IP addresses to devices on corporate networks. This vulnerability allows an authorized attacker on the same network segment to execute code with elevated privileges on the DHCP server, potentially compromising network infrastructure and gaining access to sensitive systems.
Technical details
A use-after-free vulnerability exists in the Windows DHCP Server service that allows an authenticated attacker to execute arbitrary code with the privileges of the DHCP service. The vulnerability can be exploited over an adjacent network by an authorized attacker, requiring network reachability to the DHCP server. Successful exploitation could result in remote code execution on the affected server, compromising network availability and security. A patch is expected to be available from Microsoft.
Affected products
- Microsoft Windows DHCP Server
Timeline
- 2026-09-08: disclosed