Junglewise Threat Intelligence

CVE-2026-77494: Microsoft Windows DHCP Server type confusion denial of service

CVE-2026-77494 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows DHCP Server is a critical network service that assigns IP addresses to devices on corporate networks. A type confusion vulnerability allows an attacker to crash or disable this service, preventing computers from obtaining network connectivity and disrupting business operations.

Technical details

This vulnerability is a type confusion flaw (CWE-843) in Microsoft Windows DHCP Server that allows an attacker to trigger a denial of service condition. The vulnerability can be exploited over the network without requiring authentication. By sending specially crafted requests that cause incompatible type access, an attacker can crash the DHCP Server process, preventing legitimate clients from obtaining IP address assignments. A patch is available from Microsoft.

Affected products

  • Microsoft Windows DHCP Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats