CVE-2026-62823 – Windows DHCP Server Remote Code Execution Vulnerability

CVSS 8.8 IMPORTANT 2 Critical – Same Day Deployment

“A single malicious network packet could give an unauthenticated attacker code execution on a vulnerable DHCP server, with no user action required.”

CVE-2026-62823 is a remote code execution vulnerability in Windows DHCP Server caused by a heap-based buffer overflow. An unauthenticated attacker on an adjacent network could send a specially crafted packet to an affected DHCP service and potentially execute code on the target system. The attack requires no privileges, no authentication, and no user interaction.

Key Details

Affected Product
Microsoft Windows 10 1607
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.