Description
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Assess Impact
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in the Windows DHCP Server stack that allows an unauthenticated attacker to read memory contents over the network. This results in an information disclosure that can compromise the confidentiality of sensitive data such as configuration parameters, user credentials, or internal network information. The weakness is described by CWE‑125.

Affected Systems

Affected products include Microsoft Windows 10 versions 1607 and 1809 as well as Windows Server 2012 through 2025 (both full and Server Core installations). The vulnerability applies to both 32‑bit and 64‑bit builds as indicated by the listed CPEs.

Risk and Exploitability

The CVSS score of 5.9 labels the flaw as moderate, and it is not currently listed in the CISA KEV catalog. No EPSS score is available, so the current exploitation probability cannot be quantified. The description indicates that an unauthorized attacker can exploit the flaw via network traffic to the DHCP service, implying no privileged credentials are required. Because this is an information‑disclosure flaw that can be triggered anonymously, environments that host the DHCP service should treat the risk as moderate until a patch is applied.

Generated by OpenCVE AI on September 9, 2026 at 00:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update from the update guide for the vulnerable Windows release.
  • If a patch is not yet available, isolate the DHCP server by using network segmentation and firewall rules that allow DHCP traffic only from trusted sources, and monitor DHCP logs for suspicious requests.
  • Disable the DHCP server or replace it with a hardened third‑party implementation if the service is not required.

Generated by OpenCVE AI on September 9, 2026 at 00:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
Title Windows DHCP Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows Server 2012 Windows Server 2012 (server Core Installation) Windows Server 2012 R2 Windows Server 2012 R2 Windows Server 2012 R2 (server Core Installation) Windows Server 2016 Windows Server 2016 (server Core Installation) Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:07.022Z

Reserved: 2026-08-03T22:59:57.548Z

Link: CVE-2026-69930

cve-icon Vulnrichment

Updated: 2026-09-08T20:21:34.667Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:02.880

Modified: 2026-09-24T23:18:36.947

Link: CVE-2026-69930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:06:52Z

Weaknesses