SB2026081269 - Multiple vulnerabilities in Microsoft Windows DHCP Server
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 14 vulnerabilities.
1) Integer underflow (CVE-ID: CVE-2026-62716)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to integer underflow in Windows DHCP Server. A remote attacker on the local network can send a specially crafted request to the affected application, trigger integer underflow and gain access to sensitive information on the target system.
2) Link following (CVE-ID: CVE-2026-62803)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Windows DHCP Server. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
3) Integer underflow (CVE-ID: CVE-2026-62814)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to integer underflow in Windows DHCP Server. A remote attacker on the local network can send a specially crafted request to the affected application, trigger integer underflow and gain access to sensitive information on the target system.
4) Link following (CVE-ID: CVE-2026-62807)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Windows DHCP Server. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
5) Link following (CVE-ID: CVE-2026-62761)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Windows DHCP Server. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
6) Integer underflow (CVE-ID: CVE-2026-62718)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to integer underflow in Windows DHCP Server. A remote attacker on the local network can send a specially crafted request to the affected application, trigger integer underflow and gain access to sensitive information on the target system.
7) Integer underflow (CVE-ID: CVE-2026-62745)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to integer underflow in Windows DHCP Server. A remote attacker on the local network can send a specially crafted request to the affected application, trigger integer underflow and gain access to sensitive information on the target system.
8) Integer underflow (CVE-ID: CVE-2026-62714)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to integer underflow in Windows DHCP Server. A remote attacker on the local network can send a specially crafted request to the affected application, trigger integer underflow and gain access to sensitive information on the target system.
9) Heap-based buffer overflow (CVE-ID: CVE-2026-62823)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Windows DHCP Server. A remote attacker on the local network can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
10) Integer underflow (CVE-ID: CVE-2026-62742)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to integer underflow in Windows DHCP Server. A remote attacker on the local network can send a specially crafted request to the affected application, trigger integer underflow and gain access to sensitive information on the target system.
11) Link following (CVE-ID: CVE-2026-62776)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Windows DHCP Server. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
12) Integer underflow (CVE-ID: CVE-2026-62715)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to integer underflow in Windows DHCP Server. A remote attacker on the local network can send a specially crafted request to the affected application, trigger integer underflow and gain access to sensitive information on the target system.
13) Integer underflow (CVE-ID: CVE-2026-62720)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to integer underflow in Windows DHCP Server. A remote attacker on the local network can send a specially crafted request to the affected application, trigger integer underflow and gain access to sensitive information on the target system.
14) Link following (CVE-ID: CVE-2026-62812)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Windows DHCP Server. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Remediation
Install update from vendor's website.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62716
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62803
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62814
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62807
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62761
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62718
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62745
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62714
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62742
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62776
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62715
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62720
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62812