CVE-2026-77498
massOut-of-bounds Read DoS in Microsoft Windows DHCP Server
This vulnerability is an out-of-bounds read (CWE-125) in the Microsoft Windows DHCP Server role, where the service reads beyond the bounds of an allocated memory buffer while processing network input. A remote, unauthenticated attacker can trigger it by sending crafted DHCP protocol messages to a vulnerable server, with no credentials or user interaction required. The impact is denial of service: the DHCP service can crash or stop responding, leaving clients unable to obtain IP addresses and disrupting connectivity on the affected network, with no confidentiality or integrity impact according to the CVSS score. Any organization running the DHCP Server role on Windows Server is potentially affected; the available data does not specify which Windows Server versions or builds are vulnerable. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.8% probability of exploitation within 30 days, so no confirmed exploitation is known.
What to do: Apply the Microsoft security update that addresses CVE-2026-77498 to all servers running the DHCP Server role via your normal Windows Update/WSUS patch process. As an interim measure, restrict reachability of the DHCP service (UDP 67/68) to trusted network segments and monitor for DHCP service crashes or unexpected restarts; given the absence of known exploitation or a public PoC, this can follow your standard high-severity patch cycle, but note that an unauthenticated DoS against DHCP can cut off network access for an entire site.
| Microsoft Windows DHCP Server (DHCP Server role on Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.