CVE-2026-69930
massOut-of-bounds read in Windows DHCP Server enables unauthenticated information disclosure
CVE-2026-69930 is an out-of-bounds read (CWE-125) in the Windows DHCP Server service that Microsoft rates High (CVSS 3.1: 7.5) because it is reachable over the network without authentication or user interaction. An attacker who can send crafted DHCP packets to a vulnerable Windows machine running the DHCP Server role can trigger the service to read beyond allocated memory and disclose the contents of that memory. The attacker gains access to potentially sensitive information from server memory (confidentiality impact is rated High), with no integrity or availability impact indicated in the scoring. Affected systems are Windows clients and Windows Servers with the DHCP Server role enabled — spanning Windows 10 1607/1809 and Windows Server 2012 through 2025 — which in practice typically means internal enterprise DHCP servers rather than internet-facing hosts. There is no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog; EPSS currently assigns about a 0.8% probability of exploitation within 30 days.
What to do: Inventory Windows hosts with the DHCP Server role enabled (e.g., via Get-WindowsFeature DHCP or checking the DHCP Server service state) and apply Microsoft's security update for CVE-2026-69930 as provided for each affected version, noting that 1607/1809 and older server builds may receive fixes only through extended-support/ESU channels depending on the build. Until patched, restrict which network segments and clients can reach the DHCP service (UDP 67/68), especially from untrusted or guest networks. With no public PoC or in-the-wild exploitation reported, prioritize patching by network exposure rather than observed attack activity.
| microsoft Windows 10 1607 | — |
| microsoft Windows 10 1809 | — |
| microsoft Windows Server 2012 | — |
| microsoft Windows Server 2016 | — |
| microsoft Windows Server 2019 | — |
| microsoft Windows Server 2022 | — |
| microsoft Windows Server 2025 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.