CVE-2026-69547
massHeap Buffer Overflow in Windows DHCP Server Allows Network Code Execution
CVE-2026-69547 is a heap-based buffer overflow (CWE-122) in the DHCP Server component of Microsoft Windows. By sending crafted DHCP traffic over the network, an authorized, low-privilege attacker can corrupt heap memory in the DHCP Server service, potentially executing arbitrary code with the privileges of that service. Successful exploitation carries high impact on confidentiality, integrity, and availability of the affected server (CVSS 3.1: 8.8). Organizations running the Microsoft DHCP Server role on Windows Server are in scope; the available data does not enumerate specific affected version ranges. There is no known public proof of concept, the flaw is not in CISA's KEV, and EPSS puts 30-day exploitation probability at roughly 0.9% (58th percentile), indicating no known exploitation at this time.
What to do: Monitor Microsoft's advisory and apply the security update for affected Windows Server versions as soon as it is released. Until patched, restrict reachability of the DHCP service (UDP 67/68) to trusted network segments and monitor DHCP service health and logs for anomalous client traffic. Confirm whether the DHCP Server role is installed on your Windows Servers (e.g., via the Server Manager/DISM role inventory) to prioritize patching.
| Microsoft Windows DHCP Server (DHCP Server role on Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.