CVE-2026-69845

9.8

Microsoft · Windows DHCP Server

A heap-based buffer overflow in the Windows DHCP Server allows unauthenticated, remote attackers to execute arbitrary code.

Executive summary

This critical vulnerability in the Windows DHCP Server allows unauthenticated remote code execution, posing a severe threat to network infrastructure.

Vulnerability

The vulnerability is a heap-based buffer overflow (CWE-122) stemming from improper input validation (CWE-20) within the DHCP service. An unauthenticated attacker can send a specially crafted packet to the target server to trigger this overflow and achieve remote code execution.

Business impact

The CVSS score of 9.8 reflects the extreme severity of this flaw, as it requires no user interaction or authentication to exploit. Successful exploitation could lead to a total compromise of the affected server, resulting in unauthorized data access, network disruption, and potential lateral movement throughout the enterprise environment.

Remediation

Immediate Action: Apply the vendor-supplied security updates immediately for the specific Windows versions listed in the enrichment data.

Proactive Monitoring: Monitor network traffic for anomalous DHCP packets or unexpected service restarts that may indicate exploitation attempts.

Compensating Controls: Restrict access to the DHCP service to trusted network segments using host-based firewalls or network access control lists to reduce the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of this heap-based buffer overflow and its potential for full system compromise, organizations must prioritize patching the affected DHCP Server instances. Ensure that all identified versions are updated to the specified fixed builds as soon as possible to mitigate the risk of remote code execution.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources