Junglewise Threat Intelligence

CVE-2026-77895: Microsoft Windows DHCP Server out-of-bounds read

CVE-2026-77895 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows DHCP Server is a core networking service that automatically assigns IP addresses to devices on corporate networks. An attacker on the network can trigger an out-of-bounds memory read that crashes the DHCP service, disrupting network connectivity and preventing devices from obtaining IP addresses until the service is manually restarted.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Windows DHCP Server where specially crafted DHCP requests can trigger memory access outside allocated buffer boundaries. The vulnerability is reachable over the network without authentication; an attacker can send malicious DHCP packets to trigger the out-of-bounds read condition. Successful exploitation causes a denial of service by crashing the DHCP server process, preventing legitimate DHCP clients from obtaining leases. A patch is expected to be available through Microsoft Security Updates.

Affected products

  • Microsoft Windows DHCP Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats