Description
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Score: 7.5 High
EPSS: 1.2% Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The CVE notes an out‑of‑bounds read in the Windows DHCP Server. The primary impact is that the DHCP service crashes, causing a denial of service to clients. This conclusion is inferred from the description stating the service terminates; the CVE does not explicitly describe the attacker’s input or crash mechanism.

Affected Systems

Microsoft Windows 10 versions 1607 and 1809 and Windows Server releases from 2012 to 2025, including Server Core installations, are affected. The vulnerability resides in the DHCP server component.

Risk and Exploitability

The flaw has a CVSS score of 7.5, classified as high severity. The EPSS score is reported as less than 1%, indicating exploitation is considered rare, but the CVE does not specify the exact conditions. It is inferred that an unauthenticated attacker on the same network could trigger the exploit, as the DHCP protocol is broadcast-based. The vulnerability is not listed in CISA KEV, so it is not known to be actively exploited in the wild. Monitoring for unexpected DHCP resets could help detect attacks, though the CVE does not provide evidence that such monitoring is effective.

Generated by OpenCVE AI on September 9, 2026 at 23:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows update that addresses CVE‑2026‑77501 to all affected Windows 10 and Windows Server platforms, as listed in the Microsoft Security Update Guide.
  • If a patch cannot be applied immediately, isolate the DHCP server from untrusted networks or block unauthenticated DHCP traffic with firewall rules.
  • Enable DHCP logging, monitor for repeated request anomalies, and consider temporarily disabling the DHCP service during a targeted attack.

Generated by OpenCVE AI on September 9, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2012 (server Core Installation)
Microsoft windows Server 2012 R2
Microsoft windows Server 2012 R2 (server Core Installation)
Microsoft windows Server 2016 (server Core Installation)
Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Tue, 08 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Title Windows DHCP Server Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows Server 2012 Windows Server 2012 (server Core Installation) Windows Server 2012 R2 Windows Server 2012 R2 Windows Server 2012 R2 (server Core Installation) Windows Server 2016 Windows Server 2016 (server Core Installation) Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:18.774Z

Reserved: 2026-08-20T20:11:33.673Z

Link: CVE-2026-77501

cve-icon Vulnrichment

Updated: 2026-09-08T20:54:02.149Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:37.050

Modified: 2026-09-24T23:19:00.793

Link: CVE-2026-77501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:06:09Z

Weaknesses