Executive brief
Windows DHCP Server, a critical network service responsible for assigning IP addresses to devices on a corporate network, contains a type confusion vulnerability that allows an attacker to crash the service and disrupt network connectivity for all affected devices. An attacker with network access can exploit this flaw to cause a denial of service, leaving users unable to obtain IP addresses and potentially interrupting business operations.
Technical details
This vulnerability is a type confusion flaw in Windows DHCP Server that allows an attacker to send specially crafted network packets that cause the service to mishandle resource access. The vulnerability is reachable over the network without requiring authentication. By exploiting this type confusion, an attacker can trigger a crash or hang of the DHCP Server process, resulting in denial of service. The attack does not require user interaction. Patches are available through Microsoft's standard security update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed