Junglewise Threat Intelligence

CVE-2026-77887: Microsoft Windows DHCP Server out-of-bounds read

CVE-2026-77887 · Severity: medium · CVSS 6.4 · Published 2026-09-08

Executive brief

Windows DHCP Server is a network service that assigns IP addresses to devices on corporate networks. An authenticated attacker with local system access could exploit an out-of-bounds read vulnerability to execute arbitrary code with elevated privileges, potentially compromising server integrity and enabling lateral movement across the network.

Technical details

The vulnerability is an out-of-bounds read in the Windows DHCP Server component that allows code execution. An authorized attacker with local access to the system can trigger the out-of-bounds read condition, which leads to code execution with DHCP Server privileges. The attack requires prior authentication and local system access; the vulnerability is not network-remotely exploitable. Successful exploitation grants the attacker the ability to execute arbitrary code in the context of the DHCP Server service, potentially enabling privilege escalation or lateral network movement. A security update is available from Microsoft.

Affected products

  • Microsoft Windows DHCP Server

Timeline

  • 2026-09-08: disclosed

References

Related threats