CVE-2026-77893
massOut-of-bounds Read in Windows DHCP Server Enables Unauthenticated DoS
CVE-2026-77893 is an out-of-bounds read (CWE-125) in the Windows DHCP Server role, a memory-safety flaw in how the service processes network input. An unauthenticated attacker on a network that can reach the DHCP service can send crafted traffic that triggers the out-of-bounds read, causing the DHCP Server service to fail. The impact is complete loss of availability of the affected service (CVSS availability impact High); confidentiality and integrity are not affected, but a crashed DHCP server can disrupt address assignment for the clients it serves. Any organization running the DHCP Server role on Windows Server is potentially affected, particularly where untrusted devices or users can reach the service. As of this analysis there is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns a low 0.8% probability of exploitation within 30 days (56th percentile).
What to do: Install the Microsoft security update that addresses CVE-2026-77893 as soon as it is available for your Windows Server versions (check Microsoft's advisory for the exact affected builds). In the interim, verify whether the DHCP Server role is installed (e.g., Get-WindowsFeature DHCP) and restrict network access to the DHCP service (UDP 67) to trusted network segments. Monitor DHCP service availability and event logs for crashes or restarts, since an exploit would manifest as denial of service.
| Microsoft Windows DHCP Server (DHCP Server role in Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.