ZeroHour

CVE-2026-69930

mass

Out-of-bounds read in Windows DHCP Server enables unauthenticated information disclosure

CVSS 3.1
7.5 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-69930 is an out-of-bounds read (CWE-125) in the Windows DHCP Server service that Microsoft rates High (CVSS 3.1: 7.5) because it is reachable over the network without authentication or user interaction. An attacker who can send crafted DHCP packets to a vulnerable Windows machine running the DHCP Server role can trigger the service to read beyond allocated memory and disclose the contents of that memory. The attacker gains access to potentially sensitive information from server memory (confidentiality impact is rated High), with no integrity or availability impact indicated in the scoring. Affected systems are Windows clients and Windows Servers with the DHCP Server role enabled — spanning Windows 10 1607/1809 and Windows Server 2012 through 2025 — which in practice typically means internal enterprise DHCP servers rather than internet-facing hosts. There is no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog; EPSS currently assigns about a 0.8% probability of exploitation within 30 days.

What to do: Inventory Windows hosts with the DHCP Server role enabled (e.g., via Get-WindowsFeature DHCP or checking the DHCP Server service state) and apply Microsoft's security update for CVE-2026-69930 as provided for each affected version, noting that 1607/1809 and older server builds may receive fixes only through extended-support/ESU channels depending on the build. Until patched, restrict which network segments and clients can reach the DHCP service (UDP 67/68), especially from untrusted or guest networks. With no public PoC or in-the-wild exploitation reported, prioritize patching by network exposure rather than observed attack activity.

Affected
microsoft Windows 10 1607
microsoft Windows 10 1809
microsoft Windows Server 2012
microsoft Windows Server 2016
microsoft Windows Server 2019
microsoft Windows Server 2022
microsoft Windows Server 2025
Estimated exposure
mass≈100,000+ installations worldwide (Windows machines with the DHCP Server role enabled); clearly an estimate — No public scan counts exist for this flaw, so the estimate reflects the ubiquity of the Microsoft DHCP Server role as a standard enterprise/domain network service across the very large installed base of Windows Server 2012–2025 and Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.