CVE-2026-69781: Windows DHCP Client Denial of Service Vulnerability
Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.
Other sources
Windows DHCP Client Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2954Patch KB5124012 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.9445Patch KB5124008 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33438Patch KB5122871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9445Patch KB5124008
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
The affected software listed is Microsoft Windows 11 and Microsoft Windows Server 2025. Exploitation is possible from an adjacent network, so systems that can receive DHCP-related traffic from an attacker on a neighboring network segment are the relevant exposure scope.
Does an attacker need credentials or user interaction?
No. The supplied vector indicates no privileges are required and no user interaction is needed, although the attacker must have adjacent-network access.
What is the expected impact of successful exploitation?
The stated impact is denial of service caused by memory not being released after its effective lifetime. The supplied metrics indicate no confidentiality or integrity impact, with availability impact rated high.