ZeroHour

CVE-2026-77888

mass

Unauthenticated Type Confusion DoS in Windows DHCP Server

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-77888 is a type confusion flaw (CWE-843) in the Windows DHCP Server role that lets an unauthenticated remote attacker crash or hang the service. It is triggered by sending crafted network traffic to the DHCP service, which processes data using an incompatible type and fails; no privileges or user interaction are required. An attacker gains only denial of service (confidentiality and integrity are unaffected), but a successful attack could disrupt address assignment for the clients that depend on that DHCP server. Any organization running the DHCP Server role on Windows Server is affected, with exposure greatest where the service is reachable from untrusted or broadly accessible network segments. As of this analysis there is no known public proof-of-concept, no CISA KEV listing, and a low 0.9% EPSS probability of exploitation within 30 days, indicating no confirmed in-the-wild exploitation.

What to do: Apply Microsoft's security update for CVE-2026-77888 on all Windows Server systems that have the DHCP Server role enabled, prioritizing servers reachable from untrusted networks or large client populations. Until patching is complete, restrict which network segments can send traffic to the DHCP service and monitor those servers for service crashes or restarts. Confirm exposure by inventorying servers with the DHCP role (e.g., via Get-WindowsFeature or your configuration management data) rather than assuming default configurations.

Affected
Microsoft Windows DHCP Server (DHCP Server role in Windows Server)
Estimated exposure
mass≈hundreds of thousands of Windows Server instances with the DHCP Server role enabled worldwide; far fewer are internet-exposed since most DHCP servers serve… — DHCP is one of the most commonly deployed Windows Server infrastructure roles and the global Windows Server installed base is in the millions, so the number of systems running this role plausibly exceeds 100,000, though the attack…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.