Junglewise Threat Intelligence

CVE-2026-77499: Microsoft Windows DHCP Server type confusion denial of service

CVE-2026-77499 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows DHCP Server is a core networking component that assigns IP addresses to devices on a corporate network. A type confusion vulnerability allows an unauthenticated attacker to crash the DHCP service over the network, preventing devices from obtaining IP addresses and disrupting network connectivity across the organization.

Technical details

A type confusion vulnerability exists in Windows DHCP Server where the application accesses a resource using an incompatible type, leading to memory corruption. The vulnerability can be exploited over the network by an unauthenticated attacker through specially crafted DHCP requests. Successful exploitation results in denial of service, crashing the DHCP service and rendering it unable to assign IP addresses. No authentication is required to trigger the vulnerability. A patch is available from Microsoft.

Affected products

  • Microsoft Windows Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats