Executive brief
Windows DHCP Server is a core networking service that automatically assigns IP addresses to devices on corporate networks. An attacker on the network can trigger an out-of-bounds memory read that crashes the DHCP service, disrupting network connectivity and preventing devices from obtaining IP addresses until the service is manually restarted.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Windows DHCP Server where specially crafted DHCP requests can trigger memory access outside allocated buffer boundaries. The vulnerability is reachable over the network without authentication; an attacker can send malicious DHCP packets to trigger the out-of-bounds read condition. Successful exploitation causes a denial of service by crashing the DHCP server process, preventing legitimate DHCP clients from obtaining leases. A patch is expected to be available through Microsoft Security Updates.
Affected products
- Microsoft Windows DHCP Server <UNKNOWN>
Timeline
- 2026-09-08: disclosed