Junglewise Threat Intelligence

CVE-2026-69929: Microsoft Windows DHCP Server out-of-bounds read

CVE-2026-69929 · Severity: medium · CVSS 5.9 · Published 2026-09-08

Executive brief

Microsoft Windows DHCP Server contains an out-of-bounds read vulnerability that allows an attacker on the network to access sensitive information from the DHCP service without authentication. DHCP is a critical networking service used to assign IP addresses to devices on corporate and home networks. Successful exploitation could lead to disclosure of confidential data transmitted through the DHCP protocol.

Technical details

The vulnerability is an out-of-bounds read in the Windows DHCP Server component, allowing information disclosure through network access. The flaw permits an unauthenticated attacker to read memory beyond intended boundaries in the DHCP service, potentially exposing sensitive configuration or operational data. The attack is network-accessible and requires no authentication, with exploitation triggering the out-of-bounds memory read during DHCP packet processing. An attacker can trigger the vulnerability by sending specially crafted DHCP packets to the server, resulting in information disclosure. A patch is available through the Microsoft Security Update Guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats