Junglewise Threat Intelligence

CVE-2026-77888: Microsoft Windows DHCP Server type confusion denial of service

CVE-2026-77888 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows DHCP Server, a critical network service responsible for assigning IP addresses to devices on a corporate network, contains a type confusion vulnerability that allows an attacker to crash the service and disrupt network connectivity for all affected devices. An attacker with network access can exploit this flaw to cause a denial of service, leaving users unable to obtain IP addresses and potentially interrupting business operations.

Technical details

This vulnerability is a type confusion flaw in Windows DHCP Server that allows an attacker to send specially crafted network packets that cause the service to mishandle resource access. The vulnerability is reachable over the network without requiring authentication. By exploiting this type confusion, an attacker can trigger a crash or hang of the DHCP Server process, resulting in denial of service. The attack does not require user interaction. Patches are available through Microsoft's standard security update process.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats