Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-65785

CVE-2026-65785: Windows 11 24H2 DHCP Client DoS Vulnerability

CVE-2026-65785 is a denial of service flaw in Windows 11 24H2 DHCP Client caused by uncontrolled resource consumption. Attackers on adjacent networks can exploit this to deny service without authorization.

Published:

CVE-2026-65785 Overview

CVE-2026-65785 is a denial-of-service vulnerability in the Windows Dynamic Host Configuration Protocol (DHCP) Client. The flaw stems from uncontrolled resource consumption [CWE-400] in the client component that processes DHCP responses. An unauthorized attacker on an adjacent network can exhaust resources on the target host and interrupt service availability. Exploitation requires no privileges and no user interaction, but the attacker must have layer-2 adjacency such as the same broadcast domain or Wi-Fi segment. Microsoft published the advisory on 2026-08-11 and last updated it on 2026-08-13. The vulnerability affects Windows 11 (24H2, 25H2, 26H1) and Windows Server 2025 on both x64 and ARM64 architectures.

Critical Impact

An adjacent-network attacker can send crafted DHCP traffic that exhausts client resources, causing loss of network availability on affected Windows 11 and Windows Server 2025 systems.

Affected Products

  • Microsoft Windows 11 24H2 (x64, ARM64)
  • Microsoft Windows 11 25H2 (x64, ARM64)
  • Microsoft Windows 11 26H1 (x64, ARM64)
  • Microsoft Windows Server 2025

Discovery Timeline

  • 2026-08-11 - CVE-2026-65785 published to NVD and Microsoft advisory released
  • 2026-08-13 - Last updated in NVD database

Technical Details for CVE-2026-65785

Vulnerability Analysis

The vulnerability resides in the Windows DHCP Client service, which handles address acquisition and lease renewal for network interfaces. The client fails to apply adequate bounds on resources allocated while parsing or tracking incoming DHCP messages. An attacker sending a sustained stream of crafted DHCPOFFER, DHCPACK, or malformed option payloads can force the client to allocate memory or processing capacity without a matching release. The condition maps to [CWE-400] Uncontrolled Resource Consumption. Successful exploitation results in loss of DHCP service, and downstream loss of network connectivity, on the targeted host. Confidentiality and integrity are not affected. The advisory does not indicate remote code execution or elevation of privilege.

Root Cause

The root cause is missing or insufficient rate limiting and lifecycle management on state maintained by the DHCP Client when handling adjacent-network protocol traffic. Attacker-controlled inputs drive resource growth without a corresponding cleanup path.

Attack Vector

Exploitation requires the attacker to reside on the same broadcast segment as the victim. This includes shared wired LANs, Wi-Fi networks, and virtualized network segments. The attacker sends crafted DHCP protocol messages targeting the client. No authentication or user interaction is required. Public proof-of-concept code is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. EPSS data from 2026-08-13 places the exploitation probability at 0.386%.

No verified proof-of-concept code is available. Refer to the Microsoft Security Update CVE-2026-65785 advisory for vendor technical details.

Detection Methods for CVE-2026-65785

Indicators of Compromise

  • Abnormally high volumes of DHCPOFFER, DHCPACK, or malformed DHCP option traffic directed at a single client interface.
  • Windows DHCP Client service (dhcp) exhibiting elevated memory or handle counts, followed by service instability or unresponsiveness.
  • Loss of IP lease renewal and interfaces transitioning to APIPA (169.254.0.0/16) addressing on multiple hosts within the same broadcast domain.

Detection Strategies

  • Monitor UDP ports 67 and 68 on client segments for traffic volumes that deviate from baseline lease activity.
  • Alert on repeated Service Control Manager events indicating Dhcp service crashes, restarts, or hangs on Windows 11 and Server 2025 endpoints.
  • Correlate endpoint telemetry showing sudden loss of network connectivity across multiple hosts sharing the same VLAN or SSID.

Monitoring Recommendations

  • Enable network flow logging on switches and wireless controllers to identify unauthorized DHCP responders and traffic spikes.
  • Track Windows event logs for DHCP client failure IDs, including 1003 and 1006, in the Microsoft-Windows-Dhcp-Client/Operational channel.
  • Baseline DHCP Client process resource usage on servers and continuously monitor for sustained deviation.

How to Mitigate CVE-2026-65785

Immediate Actions Required

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2026-65785 to all affected Windows 11 and Windows Server 2025 systems.
  • Prioritize patching of systems on shared or untrusted network segments, including guest Wi-Fi and multi-tenant VLANs.
  • Inventory ARM64 and x64 endpoints running Windows 11 24H2, 25H2, and 26H1 to confirm patch coverage.

Patch Information

Microsoft has released fixes through the standard Windows Update channel. Consult the Microsoft Security Update CVE-2026-65785 page for KB article numbers, build revisions, and deployment guidance specific to each affected release.

Workarounds

  • Enforce DHCP snooping on managed switches to block rogue DHCP servers on client-facing segments.
  • Segment untrusted devices onto isolated VLANs or SSIDs to remove adjacency to critical Windows hosts until patching completes.
  • Where feasible on servers, configure static IP addressing to reduce dependence on the DHCP Client service during the mitigation window.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.