Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-62736

CVE-2026-62736: Windows 11 Privilege Escalation Flaw

CVE-2026-62736 is a heap-based buffer overflow in the Windows 11 23H2 DHCP Client that allows authorized attackers to elevate privileges locally. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-62736 Overview

CVE-2026-62736 is a heap-based buffer overflow vulnerability in the Windows Dynamic Host Configuration Protocol (DHCP) Client component. The flaw enables an authorized local attacker to corrupt heap memory and elevate privileges on affected systems. Microsoft assigned this issue a CVSS 3.1 base score of 7.8 and classified it under CWE-122 (Heap-based Buffer Overflow). Successful exploitation results in high impact to confidentiality, integrity, and availability. The affected surface includes Windows 11 (23H2, 24H2, 25H2, 26H1) and Windows Server 2025. Microsoft published the advisory on 2026-08-11 through the Microsoft Security Response Center.

Critical Impact

A local attacker with low-privilege access can trigger heap corruption in the DHCP Client service to gain elevated privileges on Windows 11 and Windows Server 2025 systems.

Affected Products

  • Microsoft Windows 11 (23H2, 24H2, 25H2, 26H1) on x64 and ARM64
  • Microsoft Windows Server 2025
  • Windows DHCP Client service component

Discovery Timeline

  • 2026-08-11 - CVE-2026-62736 published to NVD
  • 2026-08-13 - Last updated in NVD database

Technical Details for CVE-2026-62736

Vulnerability Analysis

CVE-2026-62736 is a heap-based buffer overflow in the Windows DHCP Client service. The DHCP Client is responsible for acquiring and renewing IP configuration from DHCP servers and processes protocol messages received or handled locally. The vulnerability allows an authorized attacker to write beyond the bounds of a heap-allocated buffer during message processing. Heap corruption in a privileged Windows service creates a path to elevate from a standard user context to SYSTEM.

Exploitation requires local access and low privileges but no user interaction. The attack is contained within a single security scope, and successful exploitation impacts confidentiality, integrity, and availability. The vulnerability has not been observed in active exploitation, and CISA has not listed it in the Known Exploited Vulnerabilities catalog.

Root Cause

The root cause is improper validation of length or bounds when the DHCP Client service copies attacker-influenced data into a heap buffer. Insufficient size checks allow adjacent heap metadata or object pointers to be overwritten. This class of defect (CWE-122) is commonly exploited to hijack control flow or corrupt security-sensitive fields in privileged Windows services.

Attack Vector

An authenticated local attacker interacts with the DHCP Client service by triggering DHCP operations or supplying crafted input that reaches the vulnerable code path. When the malformed data is processed, the service overflows a heap buffer. The attacker then leverages the corruption to execute code or manipulate objects in the context of the DHCP Client service, which runs with elevated privileges. See the Microsoft advisory for vendor-specific exploitation context.

Detection Methods for CVE-2026-62736

Indicators of Compromise

  • Unexpected crashes or restarts of the Dhcp service (svchost.exe hosting the DHCP Client) recorded in the Windows System event log.
  • Creation of Windows Error Reporting (WER) dumps referencing dhcpcore.dll or dhcpcsvc.dll with heap corruption exceptions.
  • Suspicious child processes spawned from the DHCP Client service host, particularly cmd.exe, powershell.exe, or unsigned binaries.
  • Local privilege changes or new local administrator accounts created shortly after DHCP Client anomalies.

Detection Strategies

  • Monitor for process anomalies where svchost.exe hosting the DHCP Client service spawns interactive shells or writes to sensitive paths.
  • Alert on repeated crashes (Event ID 1000, 7031, 7034) tied to the DHCP Client service on the same host within a short window.
  • Correlate local logon events with subsequent privilege elevation activity following DHCP Client service instability.

Monitoring Recommendations

  • Ingest Windows System, Application, and Security event logs into a centralized analytics platform for cross-host correlation.
  • Track patch state for KBs referenced in the Microsoft advisory across all Windows 11 and Windows Server 2025 endpoints.
  • Baseline normal DHCP Client behavior and alert on deviations such as unexpected memory growth or handle counts on svchost.exe instances hosting Dhcp.

How to Mitigate CVE-2026-62736

Immediate Actions Required

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2026-62736 to all affected Windows 11 and Windows Server 2025 systems.
  • Prioritize patching on multi-user systems, jump hosts, and terminal servers where local low-privilege access is more likely.
  • Restrict interactive and remote local logon rights to reduce the population of users who can trigger the vulnerable code path.
  • Audit local accounts and remove unnecessary standard user access on servers running Windows Server 2025.

Patch Information

Microsoft has issued fixes for CVE-2026-62736 through the standard Windows Update channel. Consult the Microsoft Security Update Guide entry for the specific KB article numbers that correspond to each affected build. Confirm deployment by verifying the updated build number on all Windows 11 23H2, 24H2, 25H2, 26H1, and Windows Server 2025 hosts.

Workarounds

  • No official workaround has been published by Microsoft; patching is the required remediation.
  • Where patching must be delayed, limit local logon rights and enforce least privilege to reduce the attack surface.
  • Enable tamper-resistant logging and centralize Windows event collection to accelerate identification of exploitation attempts.
bash
# Verify patch state on affected Windows hosts
Get-HotFix | Sort-Object -Property InstalledOn -Descending | Select-Object -First 10

# Confirm current OS build against the fixed build referenced in the MSRC advisory
[System.Environment]::OSVersion.Version
(Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion').DisplayVersion

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.