Description
Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Windows DHCP Client allows an attacker to cause uncontrolled resource consumption, which can lead to a denial of service for the affected host and the adjacent network. This flaw falls under CWE‑400 and gives an unauthorized actor the ability to exhaust the client’s resources without authentication.

Affected Systems

Microsoft Windows 11 24H2, 25H2, and 26 H1, as well as Microsoft Windows Server 2025 (including Server Core installations). The affected Windows 11 releases are arm64 for 24H2 and 25H2, while 26 H1 runs on x64; the server version is affected on all architectures.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, but the EPSS score below 1 % implies that the likelihood of exploitation remains very low. The vulnerability is not listed in the CISA KEV catalog, meaning no known widespread exploitation. An attacker would need to be on the same network segment to send crafted DHCP packets that trigger the resource exhaustion; no authentication or elevated privileges are required.

Generated by OpenCVE AI on August 12, 2026 at 16:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses CVE‑2026‑65785 to all affected Windows 11 and Windows Server 2025 systems.
  • If the DHCP client is not required, disable the Windows DHCP Client service so that it cannot process incoming packets.
  • Segment the network to keep DHCP clients isolated from untrusted hosts and enforce firewall rules that limit DHCP traffic to known legitimate sources.

Generated by OpenCVE AI on August 12, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2025 (server Core Installation)

Thu, 13 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.
Title Windows DHCP Client Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-400
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:43.238Z

Reserved: 2026-07-22T21:30:09.119Z

Link: CVE-2026-65785

cve-icon Vulnrichment

Updated: 2026-08-12T13:50:35.628Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:58.120

Modified: 2026-08-13T17:07:59.977

Link: CVE-2026-65785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:15:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption