Executive brief
Windows DHCP Server, a core networking component that assigns IP addresses to devices on corporate and enterprise networks, contains an out-of-bounds read vulnerability. An attacker on the network can exploit this flaw to cause the DHCP server to crash or become unresponsive, disrupting network connectivity and preventing devices from obtaining IP addresses.
Technical details
This vulnerability is an out-of-bounds read in the Windows DHCP Server service. The flaw allows an unauthorized network-based attacker to send a specially crafted DHCP packet that triggers a read operation beyond allocated memory bounds. An attacker can trigger a denial of service by causing the DHCP Server process to crash or hang. No authentication is required to exploit this vulnerability, and the attack is network-accessible. Patches are expected to be available through Microsoft's security update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed