Executive brief
Windows DHCP Server is a critical network service that assigns IP addresses to devices on corporate networks. A type confusion vulnerability allows an attacker to crash or disable this service, preventing computers from obtaining network connectivity and disrupting business operations.
Technical details
This vulnerability is a type confusion flaw (CWE-843) in Microsoft Windows DHCP Server that allows an attacker to trigger a denial of service condition. The vulnerability can be exploited over the network without requiring authentication. By sending specially crafted requests that cause incompatible type access, an attacker can crash the DHCP Server process, preventing legitimate clients from obtaining IP address assignments. A patch is available from Microsoft.
Affected products
- Microsoft Windows DHCP Server <UNKNOWN>
Timeline
- 2026-09-08: disclosed