Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-26195

CVE-2024-26195: Windows Server 2008 DHCP RCE Vulnerability

CVE-2024-26195 is a remote code execution vulnerability in Microsoft Windows Server 2008 DHCP Server Service that enables attackers to execute arbitrary code. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2024-26195 Overview

CVE-2024-26195 is a remote code execution vulnerability affecting the Dynamic Host Configuration Protocol (DHCP) Server Service in supported versions of Microsoft Windows Server. The flaw is tracked under [CWE-122] (Heap-based Buffer Overflow) and allows an authenticated attacker with high privileges to execute arbitrary code against a vulnerable DHCP server across the network. Microsoft published guidance in the Security Update Guide advisory (Microsoft CVE-2024-26195 Advisory).

Critical Impact

Successful exploitation results in remote code execution in the context of the DHCP Server Service, exposing enterprise IP address management, DNS registration integrity, and lateral movement paths across the network.

Affected Products

  • Microsoft Windows Server 2008 R2 SP1 (x64) through Windows Server 2012 and 2012 R2
  • Microsoft Windows Server 2016 and Windows Server 2019
  • Microsoft Windows Server 2022 and Windows Server 2022 23H2

Discovery Timeline

  • 2024-04-09 - CVE-2024-26195 published to NVD and addressed in Microsoft's April 2024 security updates
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-26195

Vulnerability Analysis

The vulnerability resides in the Windows DHCP Server Service, a role responsible for issuing IP configuration leases to clients on Windows Server deployments. The weakness is classified as a heap-based buffer overflow under [CWE-122], indicating that memory on the process heap can be corrupted through improperly validated input handled by the service.

An attacker who has already obtained high privileges on a system able to reach the DHCP service can craft input that overflows a heap allocation. The overflow can be steered to overwrite adjacent memory structures, redirect execution flow, and achieve code execution in the DHCP service context. No user interaction is required.

Because DHCP servers commonly run on domain controllers or infrastructure hosts, code execution on this service can grant footholds close to core identity and networking assets. Compromise enables manipulation of leases, DNS records tied to DHCP registrations, and pivoting into broader Active Directory infrastructure.

Root Cause

The root cause is insufficient bounds validation when the DHCP Server Service parses attacker-controlled data into a heap buffer. The service copies or processes data past the allocated size, corrupting heap metadata or adjacent objects. Microsoft has not publicly detailed the specific parsing routine involved.

Attack Vector

The attack vector is network-based against the DHCP Server Service. Exploitation requires prior high-privilege access, meaning an attacker must already possess elevated rights within the environment before reaching the vulnerable code path. This positions the flaw as a post-compromise escalation and lateral movement primitive rather than a pre-authentication internet-exposed threat.

Exploitation code is not publicly available in this dataset, and no verified proof-of-concept is provided. Refer to the Microsoft CVE-2024-26195 Advisory for vendor guidance.

Detection Methods for CVE-2024-26195

Indicators of Compromise

  • Unexpected termination, restart, or crash of the DHCPServer service on Windows Server hosts
  • Anomalous DHCP scope, lease, or option modifications not aligned with change management records
  • New or unusual child processes spawned by svchost.exe instances hosting the DHCP Server Service
  • Outbound network connections from DHCP server hosts to untrusted destinations

Detection Strategies

  • Monitor Windows Event Log channels Microsoft-Windows-Dhcp-Server/Operational and Microsoft-Windows-Dhcp-Server/AdminEvents for service errors and configuration changes
  • Baseline normal DHCP traffic and alert on malformed or oversized DHCP messages reaching UDP ports 67 and 68
  • Correlate privileged authentication events on DHCP servers with subsequent service crashes or configuration edits

Monitoring Recommendations

  • Enable command-line and process-creation auditing on all Windows Server hosts running the DHCP role
  • Forward DHCP server telemetry and Windows security events to a centralized SIEM for correlation and long-term retention
  • Track privileged account usage that touches DHCP administration groups such as DHCP Administrators

How to Mitigate CVE-2024-26195

Immediate Actions Required

  • Apply the April 2024 (and later cumulative) Microsoft security updates to all Windows Server 2008 R2 SP1, 2012, 2012 R2, 2016, 2019, 2022, and 2022 23H2 systems running the DHCP Server role
  • Inventory every host with the DHCP Server Service enabled and prioritize patching servers that are also domain controllers or run other privileged roles
  • Restrict administrative access to DHCP servers to a minimal set of tier-0 accounts protected by multi-factor authentication

Patch Information

Microsoft released fixes as part of its April 2024 Patch Tuesday. Administrators should consult the Microsoft CVE-2024-26195 Advisory to identify the correct KB article for each Windows Server version and validate installation through Get-HotFix or the Update History interface.

Workarounds

  • No official workaround is published by Microsoft. Apply the security update as the primary remediation.
  • Where patching must be delayed, tighten network segmentation so that only authorized management subnets can reach DHCP administration interfaces
  • Remove the DHCP Server role from hosts that no longer require it to reduce attack surface
bash
# Verify the DHCP Server role status and installed updates on a Windows Server host
Get-WindowsFeature -Name DHCP
Get-HotFix | Sort-Object -Property InstalledOn -Descending | Select-Object -First 20

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.