CVE-2026-77889
massUnauthenticated Type-Confusion DoS in Microsoft Windows DHCP Server
CVE-2026-77889 is a type confusion flaw (CWE-843) in the Windows DHCP Server service, in which the server accesses a resource using an incompatible type. It is triggered over the network by an unauthorized attacker who does not need privileges, credentials, or user interaction, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). A successful attack causes a high-impact denial of service only, with no confidentiality or integrity impact, meaning the DHCP service can stop allocating addresses to clients. Any organization running the DHCP Server role on Windows Server is affected, particularly environments where untrusted devices can reach the DHCP service on the network. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.9% (57th percentile).
What to do: Install Microsoft's security update for the affected Windows Server versions as published in Microsoft's advisory (no specific fixed versions are given in the available data). Restrict reachability of the DHCP service (UDP port 67) to trusted network segments, and use DHCP failover/redundancy so a temporary denial of service does not halt address assignment. Given no public PoC and sub-1% EPSS, prioritize patching by exposure, but treat DHCP outages as high business impact since affected clients lose network access.
| Microsoft Windows DHCP Server (Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.