Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-62720

CVE-2026-62720: Windows DHCP Server Information Disclosure

CVE-2026-62720 is an information disclosure flaw in Windows DHCP Server caused by an integer underflow. Attackers on adjacent networks can exploit this to access sensitive data. Learn about affected versions and fixes.

Published:

CVE-2026-62720 Overview

CVE-2026-62720 is an integer underflow vulnerability in the Windows Dynamic Host Configuration Protocol (DHCP) Server. An unauthenticated attacker on an adjacent network can trigger the flaw to disclose sensitive server memory contents. The weakness is classified as [CWE-125] Out-of-bounds Read, resulting from wraparound in size calculations that leads the DHCP service to read beyond intended buffer boundaries. Exploitation requires no user interaction and no privileges, but the attacker must reach the DHCP service from a network-adjacent position such as the same broadcast domain or VLAN.

Critical Impact

An adjacent unauthenticated attacker can read out-of-bounds memory from the Windows DHCP Server process, potentially exposing configuration data, credentials, or other sensitive information held in service memory.

Affected Products

  • Microsoft Windows Server (DHCP Server role)
  • Refer to the Microsoft CVE-2026-62720 Advisory for the complete list of affected builds
  • Systems with the DHCP Server role installed and reachable from adjacent networks

Discovery Timeline

  • 2026-08-11 - CVE-2026-62720 published to the National Vulnerability Database
  • 2026-08-12 - Last updated in NVD database

Technical Details for CVE-2026-62720

Vulnerability Analysis

The vulnerability arises when the Windows DHCP Server processes attacker-controlled fields within a DHCP message. A length or offset value participates in an arithmetic operation that underflows, wrapping around to a very large unsigned value. The service then uses that miscalculated size when reading from a buffer, causing an out-of-bounds read [CWE-125].

Because DHCP messages are parsed before authentication, an attacker only needs the ability to send crafted DHCP traffic reachable by the server. The resulting read can return adjacent process memory to the attacker through DHCP response fields, enabling information disclosure. The vulnerability affects confidentiality only; integrity and availability are not directly impacted.

The EPSS score is 0.478% at the 39th percentile, and no public exploit or CISA KEV listing exists at the time of publication.

Root Cause

The root cause is unchecked arithmetic on a length field within the DHCP message parser. When the parser subtracts a header or option length from a smaller total, the unsigned result wraps to a large value. That value is passed to a subsequent memory read without bounds validation, breaching the source buffer boundary.

Attack Vector

The attack vector is adjacent network. The attacker must be on the same layer-2 segment, VLAN, or routed DHCP relay path that the vulnerable server accepts traffic from. The attacker crafts a malformed DHCP request containing option fields that trigger the underflow. The server responds with data that includes leaked memory contents from beyond the intended read range.

No verified proof-of-concept code has been published. Technical specifics are limited to the Microsoft CVE-2026-62720 Advisory.

Detection Methods for CVE-2026-62720

Indicators of Compromise

  • Malformed DHCP DISCOVER, REQUEST, or INFORM packets containing option length fields inconsistent with the packet size
  • Unusually large volumes of DHCP traffic from a single MAC address or relay agent
  • DHCP server process (dhcpserver.exe) generating unexpected debug or crash telemetry
  • Outbound DHCP responses containing non-standard payload sizes to unfamiliar clients

Detection Strategies

  • Deploy network intrusion detection signatures that validate DHCP option length fields against total packet size
  • Enable DHCP audit logging on Windows Server and monitor for parser errors or malformed packet events
  • Correlate DHCP server memory usage anomalies with inbound traffic from adjacent segments
  • Baseline normal DHCP client behavior and alert on option combinations that deviate from RFC 2131 patterns

Monitoring Recommendations

  • Forward DHCP server event logs and packet capture data to a centralized SIEM for continuous analysis
  • Monitor Event IDs associated with DHCP service errors in the Microsoft-Windows-DHCP-Server operational log
  • Track connections to UDP ports 67 and 68 from unauthorized VLANs or subnets
  • Alert on repeated malformed DHCP packets originating from the same source within short time windows

How to Mitigate CVE-2026-62720

Immediate Actions Required

  • Apply the Microsoft security update referenced in the Microsoft CVE-2026-62720 Advisory to all Windows Servers running the DHCP Server role
  • Inventory all DHCP servers, including those on branch and lab networks, to ensure complete coverage
  • Restrict DHCP traffic to trusted VLANs using switch-level DHCP snooping and port ACLs
  • Prioritize patching servers exposed to guest, IoT, or user-access network segments

Patch Information

Microsoft has published a security update through the Microsoft Security Response Center. Administrators should consult the Microsoft CVE-2026-62720 Advisory for the specific KB article, build numbers, and installation guidance applicable to each supported Windows Server release.

Workarounds

  • Enable DHCP snooping on managed switches to drop DHCP messages from untrusted ports
  • Segment DHCP servers behind firewalls that filter traffic from untrusted adjacent networks
  • Where feasible, temporarily migrate DHCP services to appliances not affected by this CVE until patches are applied
  • Disable the DHCP Server role on hosts where the service is not actively required
bash
# Configuration example: verify DHCP server patch level and restrict access
Get-HotFix | Where-Object { $_.HotFixID -like 'KB*' } | Sort-Object InstalledOn -Descending
Get-Service DHCPServer | Select-Object Status, StartType
New-NetFirewallRule -DisplayName 'Restrict DHCP to Trusted Subnet' -Direction Inbound -Protocol UDP -LocalPort 67 -RemoteAddress 10.0.0.0/24 -Action Allow

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.