Junglewise Threat Intelligence

CVE-2026-77893: Microsoft Windows DHCP Server out-of-bounds read

CVE-2026-77893 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows DHCP Server handles network configuration requests for corporate and enterprise systems. An attacker can send a specially crafted network packet to trigger a denial-of-service condition, causing the DHCP server to crash and preventing legitimate devices from obtaining network configuration, disrupting network connectivity across an organization.

Technical details

An out-of-bounds read vulnerability exists in the Windows DHCP Server component that processes incoming DHCP protocol packets. The vulnerability can be triggered remotely over the network without authentication. An attacker can craft a malicious DHCP packet that causes the server to read memory beyond allocated bounds, leading to a denial-of-service condition (server crash). No code execution or privilege escalation is possible; the impact is limited to availability of the DHCP service.

Affected products

  • Microsoft Windows DHCP Server

Timeline

  • 2026-09-08: disclosed

References

Related threats