CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-45602

CVSS 9.1v3.1pub. 2026-06-09upd. 2026-07-20

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

🤖 AI Analysis
How it works

A remote attacker, without authentication and without user interaction, is able to carry out a tampering attack on the Windows DHCP Server service. A network vector (AV:N) with no required attack complexity (AC:L) and no required privileges (PR:N) means that the exploit can be executed directly from the network. The detailed mechanism was not disclosed in the vendor's description.

Impact

An attacker can unauthorized modify data processed by the Windows DHCP Server service (high integrity — I:H) and gain unauthorized access to sensitive information (high confidentiality — C:H), while the availability of the service is not threatened.

Mitigation & patch

Apply patches available from the vendor according to references published in the Microsoft Security Response Center (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602)

Who is affected

Systems with Windows DHCP Server role enabled — versions indicated in vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Microsoft Windows 10 1607

    OS
    Microsoft
    < 10.0.14393.9234
  • Microsoft Windows 10 1809

    OS
    Microsoft
    < 10.0.17763.8880
  • Microsoft Windows 10 21h2

    OS
    Microsoft
    < 10.0.19044.7417
  • Microsoft Windows 10 22h2

    OS
    Microsoft
    < 10.0.19045.7417
  • Microsoft Windows 11 23h2

    OS
    Microsoft
    < 10.0.22631.7219
  • Microsoft Windows 11 24h2

    OS
    Microsoft
    < 10.0.26100.8655
  • Microsoft Windows 11 25h2

    OS
    Microsoft
    < 10.0.26200.8655
  • Microsoft Windows 11 26h1

    OS
    Microsoft
    < 10.0.28000.2269
  • Microsoft Windows Server 2012

    OS
    Microsoft
    r2
  • Microsoft Windows Server 2016

    OS
    Microsoft
    < 10.0.14393.9234
  • Microsoft Windows Server 2019

    OS
    Microsoft
    < 10.0.17763.8880
  • Microsoft Windows Server 2022

    OS
    Microsoft
    < 10.0.20348.5256
  • Microsoft Windows Server 2025

    OS
    Microsoft
    < 10.0.26100.32995
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product

Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu

CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product

RCE w Windows Server Update Service (WSUS) — deserializacja danych

CVE-2020-1040CRITICAL9.0⚠ KEVPL ✓same product

RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa

CVE-2020-1350CRITICAL10.0⚠ KEVPL ✓same product

RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)

CVE-2020-0646CRITICAL9.8⚠ KEVPL ✓same product

RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych