ZeroHour

CVE-2026-69510

mass1

Unauthenticated stack buffer overflow RCE in Microsoft Windows DHCP Server

CVSS 3.1
8.1 high
EPSS
<1%p50
Published
()
Modified
AI analysis

A stack-based buffer overflow (CWE-121) in the Microsoft Windows DHCP Server component can be triggered over the network by an unauthenticated attacker, potentially leading to remote code execution on the affected host; the CVSS 'high attack complexity' score (AC:H) indicates exploitation likely depends on specific conditions rather than straightforward attacks. An attacker who successfully exploits it gains code execution with high impact on the confidentiality, integrity and availability of the DHCP server (CVSS 3.1: 8.1, High), potentially disrupting or taking control of a core IP address-assignment service. Only systems actually running the DHCP Server role/service are practically exposed to this flaw; the affected products per Microsoft's CPE data are Windows 10 versions 1607 and 1809 (LTSC/LTSB servicing branches) and Windows Server 2012, 2016, 2019, 2022 and 2025. There is currently no known exploitation, no public proof-of-concept, and the vulnerability is not in CISA's KEV catalog; EPSS estimates roughly a 0.7% (~1-in-140) probability of exploitation within 30 days (51st percentile). Defenders should still treat this as a priority network-reachable RCE given the unauthenticated attack surface presented by DHCP servers.

What to do: Install Microsoft's security update for each affected Windows version as soon as it is available, prioritizing hosts with the DHCP Server role enabled that are reachable from untrusted or user networks. As an interim measure, inventory DHCP servers and restrict which network segments can reach them (UDP 67 and DHCP relay traffic, limiting exposure to trusted relay agents and management networks). Note that Windows 10 1607/1809 (LTSC branches) and Windows Server 2012 are on extended servicing, so verify your support arrangement (LTSC/ESU) delivers the fix.

Affected
Microsoft Windows 10 (LTSB 2016 servicing branch)version 1607 (affected/patched builds per Microsoft's advisory; specific build numbers not in source data)
Microsoft Windows 10 (LTSC 2019 servicing branch)version 1809 (affected/patched builds per Microsoft's advisory; specific build numbers not in source data)
Microsoft Windows Server 2012Windows Server 2012 (affected builds per Microsoft's advisory; includes ESU-serviced installs)
Microsoft Windows Server 2016Windows Server 2016 (affected builds per Microsoft's advisory)
Microsoft Windows Server 2019Windows Server 2019 (affected builds per Microsoft's advisory)
Microsoft Windows Server 2022Windows Server 2022 (affected builds per Microsoft's advisory)
Microsoft Windows Server 2025Windows Server 2025 (affected builds per Microsoft's advisory)
Estimated exposure
mass≈ millions of Windows hosts running the DHCP Server role worldwide (order of magnitude: >1 million deployments; practical exposure limited to hosts with the… — Estimated from the ubiquity of the DHCP Server role across the very large global Windows Server installed base in enterprise and campus networks, tempered by the fact that only hosts actually running the role are exposed and DHCP (UDP 67)…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.