Executive brief
Windows DHCP Server is a core Windows networking service that handles IP address assignment for clients on a network. A heap-based buffer overflow vulnerability in this service allows an authorized attacker with local access to execute arbitrary code with system-level privileges, potentially compromising the entire server and all connected network infrastructure.
Technical details
This vulnerability is a heap-based buffer overflow in the Windows DHCP Server service. The flaw allows an authorized attacker with local access to trigger a memory corruption condition that can be exploited to execute arbitrary code in the context of the DHCP service. Successful exploitation requires local system access and administrative or DHCP-related privileges. The vulnerability does not require user interaction and can lead to complete system compromise.
Affected products
- Microsoft Windows DHCP Server
Timeline
- 2026-09-08: disclosed