ZeroHour

CVE-2026-77499

mass

Unauthenticated type-confusion DoS in Windows DHCP Server

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-77499 is a type confusion vulnerability (CWE-843) in the Windows DHCP Server role on Windows Server, where the service accesses a resource using an incompatible type when handling network input. A remote, unauthenticated attacker can trigger the flaw by sending crafted traffic to the DHCP service, requiring no privileges or user interaction per the CVSS 3.1 vector. The attacker gains denial of service only — confidentiality and integrity are unaffected — meaning a compromised or crashed DHCP server can stop issuing IP address leases and disrupt network access for its clients until the service recovers. Any organization running the Microsoft DHCP Server role on Windows Server is affected, especially where the service is reachable from network segments an attacker can access. As of the data provided there is no known exploitation: the CVE is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates roughly a 0.9% probability of exploitation within 30 days (57th percentile).

What to do: Apply Microsoft's security update for CVE-2026-77499 to all Windows servers running the DHCP Server role — consult the MSRC advisory for the specific affected Windows Server versions and KBs, since this data does not include version ranges. As an interim mitigation, limit reachability of the DHCP service (UDP 67) to trusted network segments and monitor for unexplained DHCP outages. Periodically re-check EPSS and the KEV catalog, as the flaw is remotely triggerable by unauthenticated attackers.

Affected
Microsoft Windows DHCP Server (DHCP Server role on Windows Server)
Estimated exposure
masslikely hundreds of thousands to millions of Windows DHCP server instances worldwide (Windows Server DHCP is the default enterprise DHCP platform) — Microsoft's DHCP Server ships with Windows Server and is among the most widely deployed DHCP implementations in enterprise and campus networks, so given the very large installed base of Windows Server and the commonality of the DHCP role,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.