CVE-2026-72979

9.8

Microsoft · Windows DHCP Server

A use after free vulnerability in the Windows DHCP Server allows unauthenticated remote attackers to achieve arbitrary code execution.

Executive summary

A critical use after free vulnerability in the Windows DHCP Server allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk to system integrity and availability.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Windows DHCP Server component. The vulnerability is exploitable by an unauthenticated attacker over the network, requiring no user interaction.

Business impact

The ability for an unauthenticated attacker to execute code remotely on a DHCP server represents a critical business risk. A successful exploit could lead to full system compromise, unauthorized access to sensitive network data, and significant service disruption. Given the CVSS score of 9.8, this vulnerability is classified as critical and warrants immediate attention to prevent potential lateral movement within the network.

Remediation

Immediate Action: Apply the security updates provided in the Microsoft security advisory to upgrade to the fixed build versions listed for your specific operating system.

Proactive Monitoring: Monitor DHCP server logs for unusual crashes or service restarts that may indicate exploitation attempts.

Compensating Controls: Ensure network segmentation is in place to restrict access to DHCP services to trusted subnets, and utilize network intrusion detection systems to monitor for anomalous traffic patterns directed at the DHCP service.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for remote exploitation, IT administrators should prioritize the deployment of the necessary patches. Verify that all affected Windows Server and Windows 10 instances are updated to the specified fixed versions immediately to mitigate the risk of unauthorized system access.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources