CVE-2026-77890
massType Confusion Denial-of-Service in Microsoft Windows DHCP Server
CVE-2026-77890 is a type confusion flaw (CWE-843) in the Windows DHCP Server service that Microsoft rates 7.5 (High) with network-exploitable, unauthenticated conditions. An unauthorized attacker who can send network traffic to a vulnerable DHCP server can trigger the type confusion and consume or crash the service, yielding a high-impact denial of service with no confidentiality or integrity loss. Triggering requires only network reachability to the DHCP service — no privileges or user interaction — so any client or attacker that can reach the server's DHCP endpoint is a potential source. Affected systems are Windows deployments running the DHCP Server role; the source data does not specify which Windows Server version ranges are affected. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.9% chance of exploitation in the next 30 days.
What to do: Apply Microsoft's security updates for this vulnerability as soon as they are available, prioritizing DHCP servers reachable from untrusted networks or large client populations. Until patched, restrict access to DHCP servers (e.g., firewall/ACL rules limiting UDP 67/68 traffic to legitimate client segments and blocking untrusted sources) and monitor for DHCP service crashes or restarts. Inventory Windows Servers for the DHCP Server role to confirm which hosts need remediation.
| Microsoft Windows DHCP Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.