ZeroHour

CVE-2026-77889

mass

Unauthenticated Type-Confusion DoS in Microsoft Windows DHCP Server

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-77889 is a type confusion flaw (CWE-843) in the Windows DHCP Server service, in which the server accesses a resource using an incompatible type. It is triggered over the network by an unauthorized attacker who does not need privileges, credentials, or user interaction, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). A successful attack causes a high-impact denial of service only, with no confidentiality or integrity impact, meaning the DHCP service can stop allocating addresses to clients. Any organization running the DHCP Server role on Windows Server is affected, particularly environments where untrusted devices can reach the DHCP service on the network. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.9% (57th percentile).

What to do: Install Microsoft's security update for the affected Windows Server versions as published in Microsoft's advisory (no specific fixed versions are given in the available data). Restrict reachability of the DHCP service (UDP port 67) to trusted network segments, and use DHCP failover/redundancy so a temporary denial of service does not halt address assignment. Given no public PoC and sub-1% EPSS, prioritize patching by exposure, but treat DHCP outages as high business impact since affected clients lose network access.

Affected
Microsoft Windows DHCP Server (Windows Server)
Estimated exposure
mass≈1M+ Windows Server DHCP Server role deployments worldwide (est.) — The DHCP Server role is one of the most widely deployed Windows Server roles across enterprise, government, and mid-market networks globally, so installations plausibly number in the millions, though most are internal network services…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.