ZeroHour

CVE-2026-69876

mass

Use-After-Free RCE in Microsoft Windows DHCP Server

CVSS 3.1
8.0 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-69876 is a use-after-free memory-corruption flaw in the DHCP Server role of Microsoft Windows (also tagged with CWE-415, double free). An authorized attacker positioned on an adjacent network segment can send crafted DHCP service traffic that causes the server to reuse freed memory, corrupting the process and leading to arbitrary code execution. Successful exploitation gives the attacker code execution on the DHCP server with high impact on confidentiality, integrity, and availability, and DHCP servers are core infrastructure often co-located with domain controllers, so a foothold there is a useful pivot point. Any organization running the DHCP Server role on Windows Server is potentially affected, though the flaw is limited to authorized, adjacent-network attackers rather than unauthenticated remote attackers. There is currently no known exploitation: the CVE is not in CISA KEV, has a low EPSS score (0.6%, 46th percentile), and no public proof-of-concept is known.

What to do: Inventory servers with the DHCP Server role enabled (e.g., via your configuration-management or Windows feature inventory) and apply Microsoft's security update for this CVE as soon as it is released, checking the MSRC advisory and the next Patch Tuesday. Until patched, limit which network segments and devices can reach the DHCP service on these servers and monitor for DHCP service crashes or restarts. Given the adjacent-network, authorized-attacker requirement and the low EPSS score, treat this as a standard-priority patch, prioritizing DHCP servers on core or broadly reachable segments.

Affected
Microsoft Windows DHCP Server (DHCP Server role in Windows Server)
Estimated exposure
masslikely >100,000 Windows Server instances with the DHCP Server role worldwide (order of magnitude, possibly millions) — The DHCP Server role is a core, widely deployed Windows Server role present in most Windows-centric enterprise, campus, and branch networks, and the global Windows Server installed base runs to tens of millions of instances, so well over…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-415, CWE-416
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.