CVE-2026-69342
massOut-of-bounds read in Windows DHCP Server enables unauthenticated denial of service
CVE-2026-69342 is an out-of-bounds read (CWE-125) in the Windows DHCP Server service. A remote, unauthenticated attacker can trigger the flaw by sending maliciously crafted network traffic to the DHCP service, with no credentials or user interaction required. Successful exploitation causes a high-impact availability failure — the DHCP Server service stops responding or crashes — while confidentiality and integrity are unaffected, per the CVSS vector (C:N/I:N/A:H). Any organization running the DHCP Server role on the listed Windows 10 or Windows Server releases is exposed, which in practice means the primary address-assignment service for entire enterprise networks. Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS places the 30-day exploitation probability at about 1.1% (65th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69342 on all systems running the DHCP Server role, prioritizing core-network or internet-reachable DHCP servers. As an interim mitigation, restrict which network segments and hosts can reach the DHCP service (UDP port 67) and monitor for unexplained service crashes or restarts. Start with an inventory for the DHCP Server role, since desktop Windows 10 devices without the role are not meaningfully exposed.
| microsoft Windows 10 1607 | — |
| microsoft Windows 10 1809 | — |
| microsoft Windows Server 2012 | — |
| microsoft Windows Server 2016 | — |
| microsoft Windows Server 2019 | — |
| microsoft Windows Server 2022 | — |
| microsoft Windows Server 2025 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.