CVE-2026-69412
massStack Buffer Overflow in Microsoft Windows DHCP Server Allows Adjacent-Network RCE
CVE-2026-69412 is a stack-based buffer overflow (CWE-121) in the DHCP Server component of Microsoft Windows, rated High with a CVSS 3.1 base score of 8.0. An authorized attacker located on an adjacent network segment — one with low privileges on the same network — can send maliciously crafted DHCP traffic that overflows a fixed-size stack buffer in the DHCP Server service, with no user interaction required. Successful exploitation lets the attacker execute arbitrary code in the context of the DHCP Server service, giving high impact on the confidentiality, integrity, and availability of the affected server. Affected organizations are those running the DHCP Server role on Windows Server 2012, 2016, 2019, 2022, or 2025, and on Windows 10 1607 or 1809 where that server feature is present. There is no public proof-of-concept, no known in-the-wild exploitation, the flaw is not on CISA's KEV list, and EPSS currently estimates only a 0.5% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69412 via your standard patch channel (Windows Update/WSUS/SCCM) to Windows Server 2012/2016/2019/2022/2025 and Windows 10 1607/1809 systems, prioritizing servers that actually run the DHCP Server role. Inventory which servers host the DHCP Server role and, until patched, restrict which devices and user populations (e.g., guest Wi-Fi, shared or VPN segments) can reach those DHCP servers on the network. Because the attacker needs only low privileges and no exploit or in-the-wild activity is known yet, treat patching as routine-high priority rather than emergency.
| Microsoft Windows 10 1607 | — |
| Microsoft Windows 10 1809 | — |
| Microsoft Windows Server 2012 | — |
| Microsoft Windows Server 2016 | — |
| Microsoft Windows Server 2019 | — |
| Microsoft Windows Server 2022 | — |
| Microsoft Windows Server 2025 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.