ZeroHour

CVE-2026-69845

mass

Unauthenticated Heap Overflow RCE in Microsoft Windows DHCP Server

CVSS 3.1
9.8 critical
EPSS
<1%p59
Published
()
Modified
AI analysis

CVE-2026-69845 is a heap-based buffer overflow caused by improper input validation (CWE-20/CWE-122) in the Windows DHCP Server service, letting an unauthorized remote attacker execute arbitrary code with no privileges or user interaction required. An attacker triggers it by sending specially crafted DHCP network traffic to a machine running the DHCP Server role, and successful exploitation gives full compromise of the affected host (confidentiality, integrity, and availability all rated high per the 9.8 CVSS score). Affected products span Windows 10 1607 and 1807/1809-era releases through Windows Server 2012, 2016, 2019, 2022, and 2025, meaning both legacy out-of-support and current server builds are exposed. Microsoft addressed the flaw in the September 2026 Patch Tuesday release. No public proof-of-concept or in-the-wild exploitation is known, and EPSS currently puts 30-day exploitation probability at about 1%.

What to do: Apply the September 2026 Patch Tuesday security updates to every listed Windows 10 and Windows Server build, prioritizing servers actually running the DHCP Server role (often domain controllers). Where patching is delayed, restrict UDP 67/68 traffic to trusted VLANs/segments via firewall or ACL rules so unmanaged hosts cannot send crafted DHCP packets to the server. Watch for repeated crashes of the DHCP service (dhcpserver.exe) or anomalous heap-corruption events in server logs, and confirm Windows Server 2012 systems still under your control have an extended-security-update path, since they are past mainstream support.

Affected
microsoft windows 10 16071607 (all editions/branches in this build line as listed by Microsoft)
microsoft windows 10 18091809 (LTSC/Server-equivalent branch as listed by Microsoft)
microsoft windows server 20122012 (including R2-era support as listed; extended/EOS servicing applies)
microsoft windows server 20162016 (all editions as listed)
microsoft windows server 20192019 (all editions as listed)
microsoft windows server 20222022 (all editions as listed)
microsoft windows server 20252025 (all editions as listed)
Estimated exposure
mass≈ hundreds of thousands of Windows DHCP Server deployments worldwide (order 10^5), nearly all internal/LAN-facing rather than internet-exposed — Windows Server has an install base estimated in the tens of millions and the DHCP Server role is commonly run on domain controllers and branch/office servers; DHCP (UDP 67/68) is almost never internet-facing, so public scan counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-20, CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs