ZeroHour

CVE-2026-69412

mass

Stack Buffer Overflow in Microsoft Windows DHCP Server Allows Adjacent-Network RCE

CVSS 3.1
8.0 high
EPSS
<1%p40
Published
()
Modified
AI analysis

CVE-2026-69412 is a stack-based buffer overflow (CWE-121) in the DHCP Server component of Microsoft Windows, rated High with a CVSS 3.1 base score of 8.0. An authorized attacker located on an adjacent network segment — one with low privileges on the same network — can send maliciously crafted DHCP traffic that overflows a fixed-size stack buffer in the DHCP Server service, with no user interaction required. Successful exploitation lets the attacker execute arbitrary code in the context of the DHCP Server service, giving high impact on the confidentiality, integrity, and availability of the affected server. Affected organizations are those running the DHCP Server role on Windows Server 2012, 2016, 2019, 2022, or 2025, and on Windows 10 1607 or 1809 where that server feature is present. There is no public proof-of-concept, no known in-the-wild exploitation, the flaw is not on CISA's KEV list, and EPSS currently estimates only a 0.5% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69412 via your standard patch channel (Windows Update/WSUS/SCCM) to Windows Server 2012/2016/2019/2022/2025 and Windows 10 1607/1809 systems, prioritizing servers that actually run the DHCP Server role. Inventory which servers host the DHCP Server role and, until patched, restrict which devices and user populations (e.g., guest Wi-Fi, shared or VPN segments) can reach those DHCP servers on the network. Because the attacker needs only low privileges and no exploit or in-the-wild activity is known yet, treat patching as routine-high priority rather than emergency.

Affected
Microsoft Windows 10 1607
Microsoft Windows 10 1809
Microsoft Windows Server 2012
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Microsoft Windows Server 2025
Estimated exposure
masslikely millions of installations worldwide (Windows DHCP Server role is a common deployment across the large Windows Server installed base, but only servers… — Windows Server runs on tens of millions of machines and the DHCP Server role is a standard, widely deployed enterprise service, though the affected population is limited to hosts with that role installed and the attack requires adjacent…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-121
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.