No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
A remote attacker, without authentication and without user interaction, is able to carry out a tampering attack on the Windows DHCP Server service. A network vector (AV:N) with no required attack complexity (AC:L) and no required privileges (PR:N) means that the exploit can be executed directly from the network. The detailed mechanism was not disclosed in the vendor's description.
An attacker can unauthorized modify data processed by the Windows DHCP Server service (high integrity — I:H) and gain unauthorized access to sensitive information (high confidentiality — C:H), while the availability of the service is not threatened.
Apply patches available from the vendor according to references published in the Microsoft Security Response Center (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602)
Systems with Windows DHCP Server role enabled — versions indicated in vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMicrosoft Windows 10 1607
OSMicrosoft< 10.0.14393.9234Microsoft Windows 10 1809
OSMicrosoft< 10.0.17763.8880Microsoft Windows 10 21h2
OSMicrosoft< 10.0.19044.7417Microsoft Windows 10 22h2
OSMicrosoft< 10.0.19045.7417Microsoft Windows 11 23h2
OSMicrosoft< 10.0.22631.7219Microsoft Windows 11 24h2
OSMicrosoft< 10.0.26100.8655Microsoft Windows 11 25h2
OSMicrosoft< 10.0.26200.8655Microsoft Windows 11 26h1
OSMicrosoft< 10.0.28000.2269Microsoft Windows Server 2012
OSMicrosoftr2Microsoft Windows Server 2016
OSMicrosoft< 10.0.14393.9234Microsoft Windows Server 2019
OSMicrosoft< 10.0.17763.8880Microsoft Windows Server 2022
OSMicrosoft< 10.0.20348.5256Microsoft Windows Server 2025
OSMicrosoft< 10.0.26100.32995
Related vulnerabilities
Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu
RCE w Windows Server Update Service (WSUS) — deserializacja danych
RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa
RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)
RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych