Executive brief
Windows DHCP Server, a critical networking component that assigns IP addresses to computers on corporate networks, contains a memory leak vulnerability. An attacker on the network can trigger this leak repeatedly, exhausting server memory and causing the DHCP service to become unavailable, preventing new devices from obtaining network addresses and disrupting business connectivity.
Technical details
This is a memory leak (missing release after effective lifetime) in the Windows DHCP Server component. The vulnerability allows an unauthenticated network attacker to exhaust server memory by sending specially crafted DHCP requests, leading to denial of service. The attack requires network access to the DHCP server but does not require authentication or user interaction. Successful exploitation prevents the DHCP service from functioning, blocking IP address assignment to client devices. A patch from Microsoft is available via their Security Update Guide.
Affected products
- Microsoft Windows DHCP Server <UNKNOWN>
Timeline
- 2026-09-08: disclosed