CVE-2026-45602
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: secure@microsoft.com (Secondary)
Description
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
Affected (20)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.14393.9234 | |
| Before 10.0.17763.8880 | |
| Before 10.0.19044.7417 | |
| Before 10.0.19045.7417 | |
| Before 10.0.22631.7219 | |
| Before 10.0.26100.8655 | |
| Before 10.0.26200.8655 | |
| Before 10.0.28000.2269 | |
| All versions | |
| Before 10.0.14393.9234 | |
| Before 10.0.17763.8880 | |
| Before 10.0.20348.5256 | |
| Before 10.0.26100.32995 |
Related CWEs
CWE-229
Improper Handling of Values
The product does not properly handle when the expected number of values for parameters, fields, or arguments is not provided in input, or if those values are undefined.
CWE-349
Acceptance of Extraneous Untrusted Data With Trusted Data
The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.
References (1)
Source: secure@microsoft.com
Vendor Advisory
Timeline
No history available yet.