---
cve: "CVE-2026-69929"
severity: "MEDIUM"
cvss: 5.9
epss: "0.8%"
vendor: "Microsoft"
kev: false
exploited: false
published: "2026-09-08 18:20:02"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-10-02T07:04:31+02:00"
---

# CVE-2026-69929

> 5.9 MEDIUM

## Beschreibung

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

## CNA-Record (Kanon, cvelistV5)

- CNA: **microsoft**
- State: PUBLISHED
- Stand: 2026-10-01 22:55:14
- CNA-CVSS: **5.9** (`CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## BSI-Hinweise (deutsch)

- [Microsoft Windows: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3243) — _BSI-Einstufung: kritisch_
  Ein Angreifer kann mehrere Schwachstellen in verschiedenen Versionen von Microsoft Windows Server, Microsoft Windows 10 und Microsoft Windows 11 ausnutzen, um seine Privilegien zu erhöhen, um einen Denial of Service herbeizuführen, um Informationen offenzulegen und um beliebigen Code auszuführen.

## Referenzen

- <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69929>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-69929) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
