Description
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A double free flaw in the Windows DHCP Server program enables an attacker who has authorized access to the network to execute arbitrary code. The vulnerability stems from a memory management error that can be triggered by sending specially crafted DHCP packets. Because the flaw allows code to run with the same privileges as the DHCP service, a successful exploit can compromise the entire system to the level of that service, potentially leaking confidential data, executing malware, or establishing persistence.

Affected Systems

Affected products include Microsoft Windows 10, versions 1607 and 1809, and Windows Server releases from 2012 through 2025, both on standard and core installations. The vulnerability applies to the DHCP Server component in these operating systems.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score is less than 1%, suggesting that while the probability of exploitation is low, the vulnerability remains serious. The vulnerability is not listed in CISA’s KEV catalog. An authorized network attacker can send crafted DHCP packets to the server to trigger the double free. Because the flaw requires networking access and the attacker’s packets to be processed by the DHCP service, the attack vector is network-based with the attacker needing legitimate presence on the same local network or VPN.

Generated by OpenCVE AI on July 31, 2026 at 07:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE-2026-50685 to all affected Windows 10 and Server installations.
  • Restrict DHCP traffic by configuring firewall rules or network segmentation so that only trusted subnets can reach the DHCP server.
  • Restart the DHCP service or reboot the server after the update to ensure the patch is active.

Generated by OpenCVE AI on July 31, 2026 at 07:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
Title Windows DHCP Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-415
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:25:52.717Z

Reserved: 2026-06-05T14:35:07.080Z

Link: CVE-2026-50685

cve-icon Vulnrichment

Updated: 2026-07-14T18:18:15.476Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:15:03Z

Weaknesses