ZeroHour

CVE-2026-69547

mass

Heap Buffer Overflow in Windows DHCP Server Allows Network Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-69547 is a heap-based buffer overflow (CWE-122) in the DHCP Server component of Microsoft Windows. By sending crafted DHCP traffic over the network, an authorized, low-privilege attacker can corrupt heap memory in the DHCP Server service, potentially executing arbitrary code with the privileges of that service. Successful exploitation carries high impact on confidentiality, integrity, and availability of the affected server (CVSS 3.1: 8.8). Organizations running the Microsoft DHCP Server role on Windows Server are in scope; the available data does not enumerate specific affected version ranges. There is no known public proof of concept, the flaw is not in CISA's KEV, and EPSS puts 30-day exploitation probability at roughly 0.9% (58th percentile), indicating no known exploitation at this time.

What to do: Monitor Microsoft's advisory and apply the security update for affected Windows Server versions as soon as it is released. Until patched, restrict reachability of the DHCP service (UDP 67/68) to trusted network segments and monitor DHCP service health and logs for anomalous client traffic. Confirm whether the DHCP Server role is installed on your Windows Servers (e.g., via the Server Manager/DISM role inventory) to prioritize patching.

Affected
Microsoft Windows DHCP Server (DHCP Server role on Windows Server)
Estimated exposure
mass≈hundreds of thousands of Windows DHCP Server deployments worldwide (DHCP Server is one of the most common Windows Server roles) — The DHCP Server role ships with Windows Server and is a standard, widely deployed DHCP service in enterprise, campus, and datacenter networks, so global installations plausibly exceed 100,000, though DHCP typically runs on internal…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.