ZeroHour

CVE-2026-69342

mass

Out-of-bounds read in Windows DHCP Server enables unauthenticated denial of service

CVSS 3.1
7.5 high
EPSS
1%p64
Published
()
Modified
AI analysis

CVE-2026-69342 is an out-of-bounds read (CWE-125) in the Windows DHCP Server service. A remote, unauthenticated attacker can trigger the flaw by sending maliciously crafted network traffic to the DHCP service, with no credentials or user interaction required. Successful exploitation causes a high-impact availability failure — the DHCP Server service stops responding or crashes — while confidentiality and integrity are unaffected, per the CVSS vector (C:N/I:N/A:H). Any organization running the DHCP Server role on the listed Windows 10 or Windows Server releases is exposed, which in practice means the primary address-assignment service for entire enterprise networks. Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS places the 30-day exploitation probability at about 1.1% (65th percentile).

What to do: Apply Microsoft's security update for CVE-2026-69342 on all systems running the DHCP Server role, prioritizing core-network or internet-reachable DHCP servers. As an interim mitigation, restrict which network segments and hosts can reach the DHCP service (UDP port 67) and monitor for unexplained service crashes or restarts. Start with an inventory for the DHCP Server role, since desktop Windows 10 devices without the role are not meaningfully exposed.

Affected
microsoft Windows 10 1607
microsoft Windows 10 1809
microsoft Windows Server 2012
microsoft Windows Server 2016
microsoft Windows Server 2019
microsoft Windows Server 2022
microsoft Windows Server 2025
Estimated exposure
masslikely 1M+ Windows Server installations with the DHCP Server role active (order-of-magnitude estimate) — Windows Server runs on tens of millions of systems worldwide and the DHCP Server role is one of the most commonly deployed core network services in enterprise and Active Directory environments, so even a small share of that install base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.