ZeroHour

CVE-2026-77893

mass

Out-of-bounds Read in Windows DHCP Server Enables Unauthenticated DoS

CVSS 3.1
7.5 high
EPSS
<1%p56
Published
()
Modified
AI analysis

CVE-2026-77893 is an out-of-bounds read (CWE-125) in the Windows DHCP Server role, a memory-safety flaw in how the service processes network input. An unauthenticated attacker on a network that can reach the DHCP service can send crafted traffic that triggers the out-of-bounds read, causing the DHCP Server service to fail. The impact is complete loss of availability of the affected service (CVSS availability impact High); confidentiality and integrity are not affected, but a crashed DHCP server can disrupt address assignment for the clients it serves. Any organization running the DHCP Server role on Windows Server is potentially affected, particularly where untrusted devices or users can reach the service. As of this analysis there is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns a low 0.8% probability of exploitation within 30 days (56th percentile).

What to do: Install the Microsoft security update that addresses CVE-2026-77893 as soon as it is available for your Windows Server versions (check Microsoft's advisory for the exact affected builds). In the interim, verify whether the DHCP Server role is installed (e.g., Get-WindowsFeature DHCP) and restrict network access to the DHCP service (UDP 67) to trusted network segments. Monitor DHCP service availability and event logs for crashes or restarts, since an exploit would manifest as denial of service.

Affected
Microsoft Windows DHCP Server (DHCP Server role in Windows Server)
Estimated exposure
massplausibly 100,000+ Windows Server DHCP-role deployments worldwide (estimate; DHCP is a core, widely deployed network service) — Windows Server is among the most widely deployed server operating systems and DHCP is a standard role commonly present in enterprise and site deployments, so the global installed base likely exceeds 100,000 servers, though most instances…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.