CVE-2026-77501
massOut-of-Bounds Read DoS in Microsoft Windows DHCP Server
CVE-2026-77501 is an out-of-bounds read (CWE-125) in the Microsoft Windows DHCP Server role that allows an unauthorized attacker to deny service over a network. A remote, unauthenticated attacker can trigger the flaw by sending crafted network traffic to a vulnerable DHCP server, with no user interaction required (CVSS:3.1 AV:N/AC:L/PR:N/UI:N). The impact is availability-only (C:N/I:N/A:H): a successful attack can crash or hang the DHCP service, preventing clients from obtaining or renewing IP addresses and disrupting network connectivity for dependent hosts. Any organization running the DHCP Server role on Windows Server is potentially affected, though the specific affected Windows Server version ranges are not specified in the available data. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a ~0.8% chance of exploitation within 30 days.
What to do: Apply the Microsoft patch for CVE-2026-77501 via Windows Update/WSUS as soon as it is released, checking Microsoft's advisory for the definitive list of affected Windows Server versions before prioritizing. In the interim, restrict which network segments and relay agents can reach DHCP servers (UDP 67/68), limit layer-2 access to trusted hosts, and monitor the DHCP Server service for crashes or restarts. Since no public PoC exists, focus on internet-adjacent or guest-network-reachable DHCP instances first and plan for lease-renewal outages if the service is attacked.
| Microsoft Windows DHCP Server (DHCP Server role on Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.