AI analysis
CVE-2026-69845 is a heap-based buffer overflow caused by improper input validation (CWE-20/CWE-122) in the Windows DHCP Server service, letting an unauthorized remote attacker execute arbitrary code with no privileges or user interaction required. An attacker triggers it by sending specially crafted DHCP network traffic to a machine running the DHCP Server role, and successful exploitation gives full compromise of the affected host (confidentiality, integrity, and availability all rated high per the 9.8 CVSS score). Affected products span Windows 10 1607 and 1807/1809-era releases through Windows Server 2012, 2016, 2019, 2022, and 2025, meaning both legacy out-of-support and current server builds are exposed. Microsoft addressed the flaw in the September 2026 Patch Tuesday release. No public proof-of-concept or in-the-wild exploitation is known, and EPSS currently puts 30-day exploitation probability at about 1%.
What to do: Apply the September 2026 Patch Tuesday security updates to every listed Windows 10 and Windows Server build, prioritizing servers actually running the DHCP Server role (often domain controllers). Where patching is delayed, restrict UDP 67/68 traffic to trusted VLANs/segments via firewall or ACL rules so unmanaged hosts cannot send crafted DHCP packets to the server. Watch for repeated crashes of the DHCP service (dhcpserver.exe) or anomalous heap-corruption events in server logs, and confirm Windows Server 2012 systems still under your control have an extended-security-update path, since they are past mainstream support.
Affected
| microsoft windows 10 1607 | 1607 (all editions/branches in this build line as listed by Microsoft) |
| microsoft windows 10 1809 | 1809 (LTSC/Server-equivalent branch as listed by Microsoft) |
| microsoft windows server 2012 | 2012 (including R2-era support as listed; extended/EOS servicing applies) |
| microsoft windows server 2016 | 2016 (all editions as listed) |
| microsoft windows server 2019 | 2019 (all editions as listed) |
| microsoft windows server 2022 | 2022 (all editions as listed) |
| microsoft windows server 2025 | 2025 (all editions as listed) |
Estimated exposure
mass≈ hundreds of thousands of Windows DHCP Server deployments worldwide (order 10^5), nearly all internal/LAN-facing rather than internet-exposed — Windows Server has an install base estimated in the tens of millions and the DHCP Server role is commonly run on domain controllers and branch/office servers; DHCP (UDP 67/68) is almost never internet-facing, so public scan counts…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.