CVE-2026-77502
massOut-of-bounds read denial-of-service in Microsoft Windows DHCP Server
CVE-2026-77502 is an out-of-bounds read (CWE-125) in the Windows DHCP Server service, rated 7.5 (High) with a network attack vector, low complexity, and no privileges or user interaction required. A remote, unauthenticated attacker can send crafted traffic to a system running the DHCP Server role, causing the service to read beyond an allocated buffer and crash or hang. The impact is denial of service only: confidentiality and integrity are unaffected and the CVSS scope is unchanged. Any organization running the DHCP Server role on Windows Server is potentially affected, including internal-only deployments that a network-adjacent attacker could reach. No exploitation is known: the flaw is not in CISA's KEV, no public proof-of-concept exists, and EPSS assigns a 0.8% 30-day exploitation probability (56th percentile).
What to do: Apply Microsoft's security update for this CVE as soon as it is available; the source data does not specify patched build numbers, so verify fixed versions against Microsoft's advisory. Until systems are patched, restrict which hosts can reach DHCP servers on UDP 67/68 (ACLs, network segmentation, limiting exposure to authorized clients and DHCP relays) and monitor for unexpected stops or crashes of the DHCP Server service, since an outage can leave clients unable to obtain or renew leases. Inventory any servers with the DHCP Server role installed to prioritize patching.
| Microsoft Windows DHCP Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.