ZeroHour

CVE-2026-77494

large

Unauthenticated DoS via type confusion in Microsoft Windows DHCP Server

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
AI analysis

CVE-2026-77494 is a type confusion flaw (CWE-843) in the Windows DHCP Server service, where the service accesses a resource using an incompatible type. A remote, unauthenticated attacker can trigger it by sending crafted network traffic to a DHCP Server, with no privileges or user interaction required. Successful exploitation causes high-impact loss of availability — the DHCP service can fail or become unavailable, preventing clients from obtaining IP leases — with no stated confidentiality or integrity impact. Any organization running the DHCP Server role on Windows Server is potentially affected; specific affected version ranges are not listed in the available data and should be taken from Microsoft's advisory. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 1.2% chance of exploitation within 30 days.

What to do: Identify the affected Windows Server versions in Microsoft's advisory for CVE-2026-77494 and apply the corresponding security update. As an interim mitigation, restrict reachability of the DHCP service (UDP 67/68) to trusted network segments and monitor DHCP service health for unexpected restarts. Since there is no known exploitation, public PoC, or KEV listing, patching can follow your normal cycle, but prioritize internet-reachable or critical DHCP servers given the unauthenticated remote attack vector.

Affected
Microsoft Windows DHCP Server (Windows Server)
Estimated exposure
largeon the order of 100,000+ Windows Server deployments with the DHCP role enabled (mostly internal networks); count of internet-exposed DHCP servers unknown — The DHCP Server role is one of the most commonly deployed Windows Server roles in enterprise networks, suggesting at least hundreds of thousands of instances by deployment patterns, but no public scan counts or install-base figures were…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.