ZeroHour

CVE-2026-77890

mass

Type Confusion Denial-of-Service in Microsoft Windows DHCP Server

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-77890 is a type confusion flaw (CWE-843) in the Windows DHCP Server service that Microsoft rates 7.5 (High) with network-exploitable, unauthenticated conditions. An unauthorized attacker who can send network traffic to a vulnerable DHCP server can trigger the type confusion and consume or crash the service, yielding a high-impact denial of service with no confidentiality or integrity loss. Triggering requires only network reachability to the DHCP service — no privileges or user interaction — so any client or attacker that can reach the server's DHCP endpoint is a potential source. Affected systems are Windows deployments running the DHCP Server role; the source data does not specify which Windows Server version ranges are affected. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.9% chance of exploitation in the next 30 days.

What to do: Apply Microsoft's security updates for this vulnerability as soon as they are available, prioritizing DHCP servers reachable from untrusted networks or large client populations. Until patched, restrict access to DHCP servers (e.g., firewall/ACL rules limiting UDP 67/68 traffic to legitimate client segments and blocking untrusted sources) and monitor for DHCP service crashes or restarts. Inventory Windows Servers for the DHCP Server role to confirm which hosts need remediation.

Affected
Microsoft Windows DHCP Server
Estimated exposure
masshundreds of thousands to millions of Windows Server hosts with the DHCP Server role deployed (deployment-pattern estimate; exact counts unknown) — The DHCP Server role is a standard component of enterprise Windows Server estates (AD/DHCP are commonly co-deployed), and the installed base of Windows Servers is in the millions, though most DHCP servers are internal rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.