CVE-2026-69803
massOut-of-bounds read in Windows DHCP Server allows unauthenticated info disclosure
CVE-2026-69803 is an out-of-bounds read (CWE-125) in the Windows DHCP Server service that leaks information when the service processes crafted network input from an unauthenticated host, most plausibly a malformed DHCP request on a network segment the server serves. Because the flaw requires no privileges or user interaction (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N), any attacker with network reachability to a vulnerable DHCP server could trigger the bug and read data beyond the intended buffer boundary, potentially disclosing sensitive memory contents; there is no integrity or availability impact per the CVSS scoring. Affected systems are the listed Windows client and server versions when the DHCP Server component is running — in practice, Windows Server instances acting as DHCP servers, while the Windows 10 listings matter mainly where that component is present. As of the data available, there is no known exploitation, no public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only a 0.8% chance of exploitation within 30 days.
What to do: Inventory all Windows systems with the DHCP Server role (typically reachable on UDP 67) and apply Microsoft's security update for CVE-2026-69803, prioritizing internet-facing or shared-segment DHCP servers; consult Microsoft's advisory for the exact patched builds for each OS version, since specific update identifiers are not included in the available data. Until patched, restrict network access to the DHCP service to trusted segments with firewall rules or ACLs. No exploitation is currently known, but monitor the advisory and KEV for changes.
| microsoft Windows 10 version 1607 | — |
| microsoft Windows 10 version 1809 | — |
| microsoft Windows Server 2012 | — |
| microsoft Windows Server 2016 | — |
| microsoft Windows Server 2019 | — |
| microsoft Windows Server 2022 | — |
| microsoft Windows Server 2025 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.