CVE-2026-77895
massOut-of-Bounds Read DoS in Microsoft Windows DHCP Server
An out-of-bounds read (CWE-125) in the Microsoft Windows DHCP Server service can be triggered by unauthenticated network traffic sent to the DHCP service, per the vendor-assigned CVSS vector (network attack vector, low complexity, no privileges or user interaction required). An attacker who can reach the service can cause a denial-of-service condition; availability is the only impact, with no confidentiality or integrity effect. Affected organizations are those running the DHCP Server role in Windows Server deployments, where DHCP underpins address leasing and basic network connectivity for clients. As of the available data there is no known exploitation, no public proof-of-concept, and the issue is not listed in CISA's KEV, with EPSS estimating a 1.1% probability of exploitation within 30 days (65th percentile).
What to do: Apply Microsoft's security update for CVE-2026-77895 via Windows Update when it becomes available, prioritizing servers where the DHCP Server role is installed (verify with Get-WindowsFeature DHCP or the Microsoft DHCP Server service). Until patched, restrict network reachability of DHCP servers to trusted segments and hosts to reduce exposure to unauthenticated attackers. Because the provided data does not specify affected version ranges, confirm applicability of your Windows Server versions against Microsoft's advisory before remediating.
| Microsoft Windows Server (DHCP Server role) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.