CVE-2026-69929
massOut-of-Bounds Read in Windows DHCP Server Allows Remote Information Disclosure
CVE-2026-69929 is an out-of-bounds read (CWE-125) in the Windows DHCP Server service, rated high severity (CVSS 3.1: 7.5) with confidentiality-only impact. An unauthenticated attacker who can send network traffic to an affected machine can trigger the flaw by making the DHCP service process a crafted request that reads beyond the intended buffer. The attacker gains disclosure of server memory contents; per the CVSS vector there is no code execution, tampering, or denial of service. Anyone running the DHCP Server role on Windows Server 2012, 2016, 2019, 2022, or 2025, or on the listed Windows 10 1607/1809 builds, is affected, with real-world risk concentrated on DHCP servers reachable by untrusted or guest network clients. No public proof of concept, CISA KEV listing, or known in-the-wild exploitation exists, and EPSS estimates only a ~0.8% probability of exploitation within 30 days.
What to do: Inventory servers with the DHCP Server role enabled (e.g., via Get-WindowsFeature DHCP on Windows Server or by checking for the DhcpServer service) and prioritize them for Microsoft's security update for CVE-2026-69929 through your normal patch channels. As an interim mitigation, restrict reachability of DHCP servers on UDP port 67 from untrusted or guest network segments where feasible. Monitor Microsoft's advisory for exploitation updates, since no public PoC or in-the-wild exploitation is currently documented.
| Microsoft Windows 10 1607 | 1607 (specific builds per Microsoft's advisory) |
| Microsoft Windows 10 1809 | 1809 (specific builds per Microsoft's advisory) |
| Microsoft Windows Server 2012 | 2012 (specific builds per Microsoft's advisory) |
| Microsoft Windows Server 2016 | 2016 (specific builds per Microsoft's advisory) |
| Microsoft Windows Server 2019 | 2019 (specific builds per Microsoft's advisory) |
| Microsoft Windows Server 2022 | 2022 (specific builds per Microsoft's advisory) |
| Microsoft Windows Server 2025 | 2025 (specific builds per Microsoft's advisory) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.