CVE-2026-77886
massUnauthenticated Out-of-Bounds Read DoS in Windows DHCP Server
CVE-2026-77886 is an out-of-bounds read (CWE-125) in the Windows DHCP Server role that Microsoft rates High (CVSS 7.5) with an entirely network-based, unauthenticated attack path. An attacker who can reach the DHCP service can send crafted network input that causes the server to read beyond the intended buffer boundary. The only confirmed impact is denial of service — the confidentiality and integrity impacts are nil, but availability loss is High, meaning the DHCP service can be disrupted and clients may lose address leasing. Any organization running the DHCP Server role on Windows Server is potentially affected; specific affected version ranges were not provided in the available data. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 0.8%, indicating no known exploitation to date.
What to do: Install the security update from Microsoft for affected Windows Server versions as soon as it is available in your patch channel. Until patched, restrict reachability of the DHCP Server service to trusted network segments (e.g., limit UDP 67 access and authorized DHCP relay agents) and monitor the service for crashes or abnormal traffic. Note that a successful attack primarily disrupts IP address leasing, so assess the operational impact of DHCP downtime on each site when prioritizing patching.
| Microsoft Windows DHCP Server (DHCP Server role in Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.