Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-77887

CVE-2026-77887: Windows DHCP Server RCE Vulnerability

CVE-2026-77887 is an out-of-bounds read flaw in Windows DHCP Server that enables authorized attackers to execute arbitrary code locally. This article covers the technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-77887 Overview

CVE-2026-77887 is an out-of-bounds read vulnerability [CWE-125] in the Windows Dynamic Host Configuration Protocol (DHCP) Server component. An authorized attacker with high privileges on the local system can trigger the flaw to execute arbitrary code. Microsoft published the advisory on 2026-09-08 and last updated it on 2026-09-09.

The issue affects the confidentiality, integrity, and availability of the DHCP service and the underlying host. Exploitation requires local access, high privileges, and high attack complexity, which limits practical abuse. The Exploit Prediction Scoring System (EPSS) currently rates the probability of exploitation activity as low.

Critical Impact

Successful exploitation lets an authorized local attacker execute code in the context of the Windows DHCP Server, potentially compromising host confidentiality, integrity, and availability.

Affected Products

  • Windows DHCP Server (Microsoft) — see Microsoft Security Update CVE-2026-77887 for the authoritative list of affected builds
  • Windows Server installations running the DHCP Server role
  • Systems with DHCP Server management components enabled

Discovery Timeline

  • 2026-09-08 - CVE-2026-77887 published to the National Vulnerability Database (NVD)
  • 2026-09-09 - Last updated in NVD database

Technical Details for CVE-2026-77887

Vulnerability Analysis

The vulnerability is an out-of-bounds read in the Windows DHCP Server. The service reads memory past the intended buffer boundary while processing input, exposing adjacent process memory. Attackers can leverage the resulting information disclosure and memory-state corruption to achieve arbitrary code execution in the DHCP Server process context.

Execution occurs locally, meaning the attacker must already have a session or a foothold on the target host. The advisory further specifies that the attacker must hold high privileges before attempting exploitation. Attack complexity is high, indicating that the attacker needs specific conditions or timing to reliably trigger the read.

Successful exploitation compromises the host's confidentiality, integrity, and availability. Because the DHCP Server runs with elevated service privileges, code execution here provides a path to full system compromise from an already-privileged foothold.

Root Cause

The root cause is missing or insufficient bounds checking on a memory read operation inside the DHCP Server code path [CWE-125]. When the service parses attacker-influenced structures, it dereferences pointers or indexes buffers beyond allocated boundaries. Microsoft has not published low-level technical details beyond the advisory.

Attack Vector

The attack vector is local. A user or process authenticated on the Windows host with high privileges interacts with the DHCP Server component to trigger the out-of-bounds read. No user interaction is required. See Microsoft Security Update CVE-2026-77887 for the vendor advisory.

No public proof-of-concept exploit is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Detailed exploitation mechanics have not been publicly disclosed; refer to the vendor advisory for authoritative technical details.

Detection Methods for CVE-2026-77887

Indicators of Compromise

  • Unexpected crashes or restarts of the DHCPServer service (dhcpssvc.dll) recorded in the Windows Application or System event logs
  • Abnormal child processes spawned by svchost.exe hosting the DHCP Server service
  • Access-violation exceptions or Windows Error Reporting entries referencing the DHCP Server process
  • Unusual outbound activity or new binaries created by a process running under the DHCP Server service account

Detection Strategies

  • Monitor Windows Event Log source DhcpServer for unexpected error, warning, or service-recovery events
  • Alert on process-creation events (Sysmon Event ID 1) where the parent is the DHCP Server service and the child is a shell, script host, or LOLBin
  • Correlate authenticated interactive logons on DHCP Server hosts with subsequent DHCP service anomalies to surface local privileged abuse

Monitoring Recommendations

  • Inventory all Windows Servers running the DHCP Server role and validate patch state against the Microsoft advisory
  • Audit membership of the local Administrators and DHCP Administrators groups on DHCP hosts and review recent changes
  • Forward DHCP Server, Security, and Sysmon logs to a centralized analytics platform for retention and correlation

How to Mitigate CVE-2026-77887

Immediate Actions Required

  • Apply the Microsoft security update referenced in Microsoft Security Update CVE-2026-77887 to all Windows Servers running the DHCP Server role
  • Restrict high-privilege local access on DHCP Server hosts to a minimal, audited set of administrators
  • Review recent privileged logons on DHCP Server hosts for signs of unauthorized activity

Patch Information

Microsoft has released a security update addressing CVE-2026-77887. Consult the Microsoft Security Update Guide for the definitive list of affected builds, KB article numbers, and applicable cumulative updates. Deploy the patch through Windows Update, Windows Server Update Services (WSUS), or your enterprise patch management workflow.

Workarounds

  • No official vendor workaround has been published; patching is the recommended remediation path
  • Where patching is delayed, reduce exposure by limiting the number of accounts with local administrative rights on DHCP Server hosts
  • Enforce tiered administration so DHCP Server hosts are managed only from Privileged Access Workstations (PAWs)
  • Monitor DHCP Server processes and service accounts closely until the update is deployed

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.