Executive brief
Microsoft Windows DHCP Server is a critical network service that assigns IP addresses to devices on corporate networks. An out-of-bounds read vulnerability in this service could allow a remote attacker to read sensitive information from server memory, potentially exposing configuration data, credentials, or other confidential information stored in the server process.
Technical details
The vulnerability is an out-of-bounds read in the Windows DHCP Server component, which can be exploited over the network to disclose information from server memory. The attack requires no user interaction or elevated privileges, though specific network conditions or proximity may be required to reach the service. A remote attacker can craft malicious DHCP packets to trigger the out-of-bounds read and extract sensitive data. Microsoft has released security updates to address this issue; affected systems should apply patches immediately to mitigate the risk.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed