ZeroHour

CVE-2026-70065

large

Use-After-Free in Windows DHCP Server Enables Unauthenticated Remote DoS

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
AI analysis

CVE-2026-70065 is a memory-safety flaw (CWE-401, missing release of memory after effective lifetime, commonly described as a use-after-free) in the Windows DHCP Server service. An unauthenticated attacker with network reachability to the DHCP Server service can send traffic that triggers the memory-handling error and disrupts the service. The impact is denial of service only — the CVSS vector shows no confidentiality or integrity impact but a high availability impact — so the DHCP service can crash or hang and stop serving leases. Any organization running the DHCP Server role on Windows Server is potentially affected; no specific affected version ranges are provided in the available data. No exploitation has been reported: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a 1.2% probability of exploitation within 30 days (66th percentile).

What to do: Apply Microsoft's security update for CVE-2026-70065 when released, prioritizing servers where the DHCP Server role is enabled. Until patched, restrict reachability of the DHCP service (UDP 67/68) to trusted network segments and monitor for DHCP service crashes or restarts. Inventory which Windows Servers run the DHCP Server role to scope patching, since version details are not provided in the available data.

Affected
Microsoft Windows DHCP Server (DHCP Server service/role in Windows Server)
Estimated exposure
largeon the order of 100,000–1,000,000 Windows Server deployments with the DHCP role enabled (estimate; exact counts unknown) — DHCP Server is one of the more commonly enabled roles on Windows Server, whose installed base runs to millions of hosts, implying at least hundreds of thousands of DHCP servers worldwide, though the share reachable by attackers and the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-401
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.