Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-62745

CVE-2026-62745: Windows DHCP Server Information Disclosure

CVE-2026-62745 is an information disclosure vulnerability in Windows DHCP Server caused by integer underflow. Attackers on adjacent networks can exploit this flaw to access sensitive data. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-62745 Overview

CVE-2026-62745 is an integer underflow vulnerability in the Windows Dynamic Host Configuration Protocol (DHCP) Server service. An unauthenticated attacker on an adjacent network can exploit the flaw to disclose sensitive memory contents from the DHCP server process. The weakness is classified under [CWE-125] (Out-of-Bounds Read), triggered when arithmetic on packet length fields wraps below zero and permits reads past intended buffer boundaries. Microsoft published the advisory on August 11, 2026.

Critical Impact

An adjacent-network attacker can trigger memory disclosure from the Windows DHCP Server without authentication or user interaction, exposing process memory that may include configuration data or leaked pointers.

Affected Products

  • Windows DHCP Server (see Microsoft Security Update Guide for exact build coverage)
  • Windows Server editions running the DHCP Server role
  • Consult Microsoft's advisory for the authoritative list of affected builds

Discovery Timeline

  • 2026-08-11 - CVE-2026-62745 published to NVD
  • 2026-08-11 - Last updated in NVD database

Technical Details for CVE-2026-62745

Vulnerability Analysis

The vulnerability resides in the DHCP Server service's handling of client packet fields. A signed or unsigned length value is decremented or subtracted without validating that the operand is smaller than the current size. When the subtraction underflows, the resulting value wraps to a very large positive integer. That value then drives a subsequent copy or parse loop that reads well beyond the allocated buffer, producing an out-of-bounds read condition tracked as [CWE-125].

The attack surface is the DHCP request path exposed to Layer 2 neighbors. An attacker on the same broadcast domain sends a crafted DHCP message with malformed option lengths or option counts. The server parses the packet, the arithmetic underflows, and the leaked memory is either returned in a DHCP response or influences server behavior in observable ways. The EPSS score of 0.369% suggests low near-term exploitation probability, but the pre-authentication adjacent-network vector makes segmented networks with untrusted VLANs the primary concern.

Root Cause

The root cause is missing bounds validation before performing width-narrowing arithmetic on attacker-controlled length fields. DHCP options carry length bytes, and internal parsers subtract consumed bytes from a running counter. When a crafted option declares a length larger than remaining buffer space, the counter underflows rather than being rejected, and downstream code treats the wrapped value as a valid large size.

Attack Vector

Exploitation requires network adjacency, meaning the attacker must be able to send DHCP traffic that reaches the server, typically the same broadcast domain or a relay-connected subnet. No credentials and no user interaction are required. The vulnerability does not permit code execution or modification of server state, but it does expose process memory to an unauthenticated peer.

No verified proof-of-concept code is publicly available. Technical details are described in prose because no vetted exploitation code has been released; refer to the Microsoft Security Update Guide for vendor analysis.

Detection Methods for CVE-2026-62745

Indicators of Compromise

  • Malformed DHCP DISCOVER or REQUEST packets containing option length fields that exceed the remaining packet size
  • Unexpected DHCP responses of anomalous size or with padding that does not match the requested option set
  • Repeated DHCP transactions from a single MAC address probing option parsing edge cases

Detection Strategies

  • Deploy network intrusion detection signatures that validate DHCP option length arithmetic against total packet length
  • Alert on DHCP server process memory spikes or crashes correlated with inbound client requests from a single source
  • Monitor Windows Event Log entries from the DHCP Server service for parsing errors or unexpected termination

Monitoring Recommendations

  • Baseline normal DHCP client volumes per VLAN and alert on statistical anomalies
  • Forward DHCP server logs and Windows Security events to a centralized SIEM for correlation with adjacent-network activity
  • Enable packet capture on DHCP server interfaces during patch validation windows to preserve forensic evidence

How to Mitigate CVE-2026-62745

Immediate Actions Required

  • Apply the Microsoft security update referenced in the Microsoft Security Update Guide to all Windows Servers running the DHCP Server role
  • Inventory DHCP server instances, including those on domain controllers and branch office servers, before deployment
  • Restrict Layer 2 access to DHCP server segments and audit which VLANs can reach the service

Patch Information

Microsoft released a security update addressing CVE-2026-62745 on August 11, 2026. Administrators should install the update on all systems running the Windows DHCP Server role. Refer to the Microsoft Security Update Guide for KB article numbers and the full list of affected builds.

Workarounds

  • Use DHCP relay agents that validate option length fields before forwarding traffic to the server
  • Segment untrusted networks (guest Wi-Fi, IoT VLANs) so they cannot reach production DHCP servers directly
  • Deploy port-level DHCP snooping on managed switches to drop malformed client packets at the access layer
bash
# Example: verify the DHCP Server service state and apply pending updates on Windows Server
Get-WindowsFeature -Name DHCP
Get-Service DHCPServer
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 10
# Install pending updates via PSWindowsUpdate
Install-Module PSWindowsUpdate -Force
Get-WindowsUpdate -MicrosoftUpdate -Install -AcceptAll -AutoReboot

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.