ZeroHour

CVE-2026-69620

mass

Unauthenticated Stack Buffer Overflow in Windows DHCP Server

CVSS 3.1
8.1 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-69620 is a stack-based buffer overflow (CWE-121) in the DHCP Server component of Windows. An unauthorized attacker who can send traffic to the DHCP service over a network can trigger the overflow with crafted requests; the CVSS high attack-complexity score (AC:H) indicates the trigger is not trivially reliable. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability on the affected host. Exposure is effectively limited to machines running the DHCP Server role on Windows 10 1607/1809 (LTSC) and Windows Server 2012, 2016, 2019, 2022, and 2025, which are typically domain-joined or enterprise servers. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-69620 as soon as it is available, prioritizing Windows Servers where the DHCP Server role is installed (check with Get-WindowsFeature DHCP on Server, or the DHCP Server service on the host). As interim mitigation, restrict network access to the DHCP service (UDP 67/68) to trusted management or client segments. Note that Windows Server 2012 is past mainstream support, so organizations still running it should confirm extended-security-update coverage and patch it as well.

Affected
microsoft Windows 101607
microsoft Windows 101809
microsoft Windows Server2012
microsoft Windows Server2016
microsoft Windows Server2019
microsoft Windows Server2022
microsoft Windows Server2025
Estimated exposure
mass≈ millions of Windows DHCP server instances worldwide (only hosts with the DHCP Server role are affected), though most are reachable only from internal… — The DHCP Server role is one of the most commonly deployed Windows Server roles in enterprise and Microsoft Active Directory environments, implying an install base in the millions, but per-host exposure requires an attacker with network…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.