Skip to content

CVE-2026-72979

Windows DHCP Server use-after-free vulnerability allows remote code execution (CVE-2026-72979)

Critical 9.8 Vendor: Microsoft Published

Use-after-free in Windows DHCP Server allows an unauthenticated attacker to execute code over the network. Microsoft rates the flaw critical and has released fixed builds for affected Windows Server and Windows 10 versions. Apply the September 2026 updates promptly.

What happened

Microsoft's Windows DHCP Server contains a use-after-free vulnerability (CWE-416). An unauthorised attacker can exploit it over the network with no credentials and no user interaction. The CVSS 3.1 base score is 9.8: network attack vector, low attack complexity, and high impact to confidentiality, integrity and availability.

Microsoft rates the issue Critical. No current reports of active exploitation or public disclosure are recorded for this CVE. Microsoft has not published a workaround for the vulnerability.

Who is affected

Windows DHCP Server is a role commonly deployed on Windows Server to hand out IP addresses. Microsoft lists the following affected versions, all before the fixed builds shown in the next section:

  • Windows 10 Version 1607: 10.0.14393.0 to before 10.0.14393.9512
  • Windows 10 Version 1809: 10.0.17763.0 to before 10.0.17763.9245
  • Windows Server 2012 and Server Core installation: 6.2.9200.0 to before 6.2.9200.26349
  • Windows Server 2012 R2 and Server Core installation: 6.3.9600.0 to before 6.3.9600.23398
  • Windows Server 2016 and Server Core installation: 10.0.14393.0 to before 10.0.14393.9512
  • Windows Server 2019 and Server Core installation: 10.0.17763.0 to before 10.0.17763.9245
  • Windows Server 2022: 10.0.20348.0 to before 10.0.20348.5622
  • Windows Server 2025: 10.0.26100.0 to before 10.0.26100.33438

What to do now

  1. Apply the September 2026 security updates from Microsoft to every affected system, particularly those running the Windows DHCP Server role. The fixed versions are:
  • 6.2.9200.26349 (Windows Server 2012 and Server Core installation)
  • 6.3.9600.23398 (Windows Server 2012 R2 and Server Core installation)
  • 10.0.14393.9512 (Windows 10 Version 1607; Windows Server 2016 and Server Core installation)
  • 10.0.17763.9245 (Windows 10 Version 1809; Windows Server 2019 and Server Core installation)
  • 10.0.20348.5622 (Windows Server 2022)
  • 10.0.26100.33438 (Windows Server 2025 and Server Core installation)

The corresponding update references from Microsoft are KB5123065, KB5123066, KB5123099, KB5122876, KB5122882 and KB5122871.

  1. Prioritise hosts running the DHCP Server role. Because the flaw requires no credentials or user interaction, any unpatched DHCP server reachable from a network is at risk.
  1. If you cannot patch immediately, restrict network reachability to affected servers as far as practicable until the update is installed. Microsoft has not published a workaround.

How to detect it

Microsoft has not published indicators of compromise for this issue. The practical check is exposure and patch state: inventory every system with the Windows DHCP Server role, confirm whether it is reachable from untrusted networks, and verify the fixed build numbers above after deployment.

Beyond the patch

This is a flaw where exposure is the whole story: a network-reachable, pre-authentication service on a role that often lingers unnoticed on older servers. After patching, use Virtual CISO Services (vCISO) to find and reduce exposed DHCP and similar services, and keep Managed Detection & Response (MDR) on the estate to catch post-exploitation moves.

Affected and fixed versions

ProductAffectedFixed in
Windows 10 Version 160710.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows 10 Version 180910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
Windows Server 20126.2.9200.0 – < 6.2.9200.263496.2.9200.26349
(Server Core installation) 6.2.9200.26349
R2 6.3.9600.23398
R2 (Server Core installation) 6.3.9600.23398
Windows Server 2012 (Server Core installation)6.2.9200.0 – < 6.2.9200.263496.2.9200.26349
Windows Server 2012 R26.3.9600.0 – < 6.3.9600.233986.3.9600.23398
(Server Core installation) 6.3.9600.23398
Windows Server 2012 R2 (Server Core installation)6.3.9600.0 – < 6.3.9600.233986.3.9600.23398
Windows Server 201610.0.14393.0 – < 10.0.14393.951210.0.14393.9512
(Server Core installation) 10.0.14393.9512
Windows Server 2016 (Server Core installation)10.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows Server 201910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
(Server Core installation) 10.0.17763.9245
Windows Server 2019 (Server Core installation)10.0.17763.0 – < 10.0.17763.924510.0.17763.9245
Windows Server 202210.0.20348.0 – < 10.0.20348.562210.0.20348.5622
Windows Server 202510.0.26100.0 – < 10.0.26100.3343810.0.26100.33438
(Server Core installation) 10.0.26100.33438

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.