Executive brief
Windows DHCP Server, a core networking service that assigns IP addresses to devices on corporate networks, contains an out-of-bounds memory read vulnerability. An attacker on the network can exploit this flaw to crash the DHCP service, causing new devices to fail to connect to the network and potentially disrupting business operations.
Technical details
An out-of-bounds read vulnerability exists in Windows DHCP Server that can be triggered by a specially crafted network packet. The vulnerability does not require authentication or user interaction; an attacker with network access to the DHCP service can send a malicious DHCP packet to cause a denial of service by crashing the server process. The vulnerability is rated high severity with a CVSS score of 7.5, indicating significant impact on service availability. A patch is available from Microsoft.
Affected products
- Microsoft Windows DHCP Server
Timeline
- 2026-09-08: disclosed