ZeroHour

CVE-2026-69777

mass

Heap Buffer Overflow in Windows DHCP Client Allows Adjacent Privilege Escalation

CVSS 3.1
8.0 high
EPSS
<1%p41
Published
()
Modified
AI analysis

CVE-2026-69777 is a heap-based buffer overflow (CWE-122) in the DHCP Client service built into Microsoft Windows. An attacker who already holds a low-privileged, authorized position on the same network segment (CVSS: adjacent network vector, low privileges required, no user interaction) can send crafted DHCP responses that overflow a heap buffer when the Windows DHCP Client processes them. Because the DHCP Client service runs with high privileges (typically SYSTEM) on Windows, a successful exploit lets the attacker elevate privileges and take near-complete control of the host, with high impact to confidentiality, integrity, and availability (CVSS 3.1 score 8.0, High). Any Windows system running the DHCP Client is affected — effectively nearly all Windows workstations and servers — although exploitation requires an adjacent-network attacker rather than remote or internet-based access. There is currently no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns a 0.5% probability of exploitation within 30 days (41st percentile), so no exploitation has been observed.

What to do: Deploy Microsoft's security update for CVE-2026-69777 through Windows Update / your patch management channel as soon as it is released, prioritizing endpoints and servers on shared or semi-trusted segments (office LANs, guest Wi-Fi, VLANs hosting third-party devices, VPN and wireless access networks) where an adjacent attacker is most plausible. Until systems are patched, enable DHCP snooping on switch infrastructure to block rogue DHCP servers from injecting crafted responses, and monitor the DHCP Client service for crashes or anomalous behavior. With no public PoC or in-the-wild exploitation known, routine patch-cycle prioritization is reasonable outside of high-exposure network segments.

Affected
Microsoft Windows DHCP Client (component of Microsoft Windows)
Estimated exposure
mass1 billion+ Windows devices (DHCP Client is enabled by default on essentially all Windows installations) — The DHCP Client service ships and runs by default on virtually every Windows workstation and server, and Microsoft has publicly reported an active Windows install base of more than 1.4 billion devices, so the vulnerable component is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges over an adjacent network.

Vendors
microsoft
Products
windows 11 24h2, windows 11 25h2, windows 11 26h1
Weakness
CWE-122
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.