Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has released fixes for CVE-2026-72979, Windows DHCP Server Remote Code Execution Vulnerability, a Critical flaw in Windows DHCP Server. The vulnerability is a CWE-416 use-after-free issue: an unauthorized attacker could execute code over a network by sending a specially crafted packet to an affected DHCP service. No authentication or user interaction is required, making patch deployment the only sensible item on the agenda.

Microsoft assigns the issue a CVSS base score of 9.8 and a CVSS temporal score of 8.5.

  • Severity: Critical
  • CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • CWE: CWE-416
  • Exploitation assessment: Exploitation Less Likely
  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes

Abstract illustration of connected devices separated by a protected security boundary. What Microsoft says an attacker could do​

Microsoft’s advisory describes the issue as follows: “Windows DHCP Server Remote Code Execution Vulnerability: Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.”

The company further states that an unauthenticated attacker could send a specially crafted packet to an affected service over the network. If exploitation succeeds, the attacker could execute code on the target system. In short: this is a network-reachable server-side bug, not a click-a-link or open-an-attachment scenario.

The CVSS vector reflects that exposure: low attack complexity, no privileges, no user interaction, and potentially high impact to confidentiality, integrity, and availability. DHCP may be the plumbing nobody notices until it fails, but it is still plumbing connected to every client asking where it lives on the network.

Required updates and fixed builds​

Administrators should identify systems running the affected DHCP Server role and deploy the applicable update. Microsoft maps the affected products to the following KBs and fixed builds:

Affected productUpdate and fixed build
Windows 10 Version 1607 for 32-bit Systems (x86)For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows 10 Version 1607 for x64-based SystemsFor Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
Windows 10 Version 1809 for 32-bit Systems (x86)For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows 10 Version 1809 for x64-based SystemsFor Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2012 (Server Core installation) (x64)For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
Windows Server 2012 (x64)For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
Windows Server 2012 R2 (Server Core installation) (x64)For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
Windows Server 2012 R2 (x64)For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
Windows Server 2016 (Server Core installation) (x64)For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows Server 2016 (x64)For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows Server 2019 (Server Core installation) (x64)For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2019 (x64)For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2022 (Server Core installation) (x64)For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
Windows Server 2022 (x64)For Windows Server 2022 (x64)
Windows Server 2025 (Server Core installation) (x64)For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
Windows Server 2025 (x64)For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

Administrator checklist​

  1. Inventory Windows systems that provide DHCP services, including Server Core deployments.
  2. Match each DHCP server’s Windows version and architecture to Microsoft’s KB/build mapping.
  3. Install the listed cumulative update and confirm the server reaches its specified fixed build.
  4. Include redundant or failover DHCP infrastructure in the same remediation plan; a secondary DHCP server is still a server that needs patching.
  5. Record the deployed KB and build in patch-management evidence, particularly where older Windows Server versions remain in operational use.

This advisory is notable because the attack described by Microsoft begins with a crafted network packet and does not require an attacker to authenticate or persuade a user to do anything. The pragmatic response is equally straightforward: patch every affected Windows DHCP Server instance to the Microsoft-specified fixed build.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com