Description
Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

From the description, a missing release of memory after its effective lifetime in the Windows DHCP Client allows an attacker to cause a denial of service on the host connected to an adjacent network. The flaw does not provide a path for code execution or data exfiltration; instead, it simply interrupts the DHCP client’s operation, potentially preventing the host from obtaining or renewing IP addresses and thereby disabling network connectivity. The vulnerability is mapped to CWE-401, indicating a memory management issue that can lead to resource exhaustion.

Affected Systems

Affected systems are Microsoft Windows 11 in the 24H2, 25H2, and 26H1 release tracks, as well as Microsoft Windows Server 2025, including both standard and Server Core installations. The list of CPEs reflects ARM64 builds for Windows 11 24H2 and 25H2 and an x64 build for Windows 11 26H1, with servers running on standard architectures. All current releases of these operating systems are vulnerable until the patched update is applied.

Risk and Exploitability

The CVSS score of 6.5 places this flaw in the medium severity range. No EPSS score is published, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely known exploits yet. Nevertheless, an attacker who can reach the affected host from a neighboring or compromised network segment can trigger the denial of service simply by interacting with the DHCP client, which is a local-network-level threat. System administrators should monitor DHCP service status and apply the security update as soon as it becomes available to mitigate the risk.

Generated by OpenCVE AI on September 8, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest security update from Microsoft’s Security Update Guide that addresses CVE-2026-69781 for all affected Windows 11 and Windows Server 2025 releases.
  • Deploy the patch to every affected workstation, server, and Server Core installation during a maintenance window to avoid sudden network outages.
  • If a patch cannot be applied immediately, temporarily disable the DHCP client service or configure static IP addresses on affected machines until the fixed update is installed.

Generated by OpenCVE AI on September 8, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2025 (server Core Installation)

Thu, 10 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.
Title Windows DHCP Client Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-401
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:36:34.808Z

Reserved: 2026-08-03T22:46:09.553Z

Link: CVE-2026-69781

cve-icon Vulnrichment

Updated: 2026-09-08T20:46:24.895Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:49.560

Modified: 2026-09-10T17:49:41.580

Link: CVE-2026-69781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:55:40Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime