CVE-2026-70065
largeUse-After-Free in Windows DHCP Server Enables Unauthenticated Remote DoS
CVE-2026-70065 is a memory-safety flaw (CWE-401, missing release of memory after effective lifetime, commonly described as a use-after-free) in the Windows DHCP Server service. An unauthenticated attacker with network reachability to the DHCP Server service can send traffic that triggers the memory-handling error and disrupts the service. The impact is denial of service only — the CVSS vector shows no confidentiality or integrity impact but a high availability impact — so the DHCP service can crash or hang and stop serving leases. Any organization running the DHCP Server role on Windows Server is potentially affected; no specific affected version ranges are provided in the available data. No exploitation has been reported: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a 1.2% probability of exploitation within 30 days (66th percentile).
What to do: Apply Microsoft's security update for CVE-2026-70065 when released, prioritizing servers where the DHCP Server role is enabled. Until patched, restrict reachability of the DHCP service (UDP 67/68) to trusted network segments and monitor for DHCP service crashes or restarts. Inventory which Windows Servers run the DHCP Server role to scope patching, since version details are not provided in the available data.
| Microsoft Windows DHCP Server (DHCP Server service/role in Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-401
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.