Executive brief
Windows DHCP Server is a network service that assigns IP addresses to devices on corporate networks. A type confusion vulnerability allows an unauthenticated attacker to crash the DHCP service over the network, disrupting IP address allocation and potentially rendering network connectivity unavailable for affected devices.
Technical details
A type confusion vulnerability (CWE-843) in Windows DHCP Server allows an attacker to access memory resources using an incompatible type, triggering a denial of service condition. The vulnerability is network-reachable and requires no authentication or user interaction. An attacker can send a specially crafted DHCP message to crash the DHCP Server service, preventing legitimate clients from obtaining IP addresses. A patch is available from Microsoft.
Affected products
- Microsoft Windows DHCP Server multiple versions
Timeline
- 2026-09-08: disclosed