CVE-2026-69847
massHeap buffer overflow in Windows DHCP Server enables adjacent-network RCE
CVE-2026-69847 is a heap-based buffer overflow (CWE-122) in the Windows DHCP Server role, rated High (CVSS 3.1: 8.0) and assigned by Microsoft as CNA. An authorized attacker (low privileges required) positioned on an adjacent network segment can send crafted DHCP traffic to trigger the overflow, with no user interaction required. Successful exploitation yields arbitrary code execution on the DHCP server with high impact on confidentiality, integrity, and availability. Any organization running the DHCP Server role on Windows Server is potentially affected; the adjacent-network attack vector means exposure is concentrated on internal networks rather than internet-facing systems. As of publication there is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates a 0.5% probability of exploitation within 30 days (40th percentile).
What to do: Inventory all Windows Servers with the DHCP Server role enabled and prioritize applying Microsoft's security update for CVE-2026-69847. Until patched, restrict reachability of the DHCP service (UDP 67/68) to trusted network segments and authorized relay agents/clients, and monitor for anomalous DHCP traffic from adjacent segments. Consult Microsoft's advisory for the exact affected Windows Server versions and remediation guidance, since version details are not specified in the available data.
| Microsoft Windows DHCP Server (DHCP Server role in Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.