ZeroHour

CVE-2026-77502

mass

Out-of-bounds read denial-of-service in Microsoft Windows DHCP Server

CVSS 3.1
7.5 high
EPSS
<1%p56
Published
()
Modified
AI analysis

CVE-2026-77502 is an out-of-bounds read (CWE-125) in the Windows DHCP Server service, rated 7.5 (High) with a network attack vector, low complexity, and no privileges or user interaction required. A remote, unauthenticated attacker can send crafted traffic to a system running the DHCP Server role, causing the service to read beyond an allocated buffer and crash or hang. The impact is denial of service only: confidentiality and integrity are unaffected and the CVSS scope is unchanged. Any organization running the DHCP Server role on Windows Server is potentially affected, including internal-only deployments that a network-adjacent attacker could reach. No exploitation is known: the flaw is not in CISA's KEV, no public proof-of-concept exists, and EPSS assigns a 0.8% 30-day exploitation probability (56th percentile).

What to do: Apply Microsoft's security update for this CVE as soon as it is available; the source data does not specify patched build numbers, so verify fixed versions against Microsoft's advisory. Until systems are patched, restrict which hosts can reach DHCP servers on UDP 67/68 (ACLs, network segmentation, limiting exposure to authorized clients and DHCP relays) and monitor for unexpected stops or crashes of the DHCP Server service, since an outage can leave clients unable to obtain or renew leases. Inventory any servers with the DHCP Server role installed to prioritize patching.

Affected
Microsoft Windows DHCP Server
Estimated exposure
masshundreds of thousands of Windows DHCP server deployments worldwide (Windows Server's installed base is estimated in the tens of millions and DHCP is among its… — Microsoft does not publish DHCP-role install counts, but the Windows Server installed base is estimated in the tens of millions and the DHCP Server role is a core network service routinely deployed in enterprise and Active Directory…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.