Junglewise Threat Intelligence

CVE-2026-77891: Microsoft Windows DHCP Server out-of-bounds read

CVE-2026-77891 · Severity: medium · CVSS 6.4 · Published 2026-09-08

Executive brief

Windows DHCP Server is a network service that assigns IP addresses to devices on a corporate network. An authorized user with local access could exploit an out-of-bounds read vulnerability to execute arbitrary code with elevated privileges, potentially compromising the entire network infrastructure.

Technical details

An out-of-bounds read vulnerability exists in Windows DHCP Server that allows an authenticated local attacker to read beyond allocated memory boundaries. The vulnerability requires the attacker to have local system access and valid credentials. Successful exploitation enables arbitrary code execution in the context of the DHCP Server process. A patch has been released by Microsoft; administrators should apply the security update promptly.

Affected products

  • Microsoft Windows DHCP Server

Timeline

  • 2026-09-08: disclosed

References

Related threats