Executive brief
Windows DHCP Server is a core networking component that assigns IP addresses to devices on a corporate network. An out-of-bounds read vulnerability allows a network attacker to extract sensitive information from the DHCP server's memory without needing valid credentials, potentially exposing configuration data or internal network details.
Technical details
This is an out-of-bounds read vulnerability in the Windows DHCP Server component. The vulnerability permits an unauthenticated attacker to send specially crafted network packets that trigger a memory read beyond allocated buffer boundaries, disclosing information from the server process's memory. The attack is network-reachable and requires no prior authentication or user interaction. An attacker can selectively leak sensitive data such as configuration parameters or system state. Microsoft has released security patches to address this issue.
Affected products
- Microsoft Windows DHCP Server <UNKNOWN>
Timeline
- 2026-09-08: disclosed