Executive brief
Windows DHCP Server, a critical network service that assigns IP addresses to devices, contains an out-of-bounds memory read vulnerability. An attacker on the network can exploit this flaw to crash the DHCP Server without authentication, causing all devices unable to obtain or renew network addresses. This results in a denial of service affecting network connectivity across an organization.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Windows DHCP Server that allows remote, unauthenticated denial of service. The vulnerability is triggered by malformed DHCP packets sent over the network to the DHCP Server. The out-of-bounds memory read can cause the DHCP Server process to crash, denying DHCP services to all clients. No authentication is required to exploit this vulnerability; an attacker needs only network connectivity to the DHCP Server. A patch is available from Microsoft Security Response Center.
Affected products
- Microsoft Windows DHCP Server
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: CVE-2026-77498 published on NVD