Windows DHCP Client Elevation of Privilege Vulnerability
Plan PatchCVSS 7.5CVE-2026-49181Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Integer underflow vulnerability in Windows DHCP Client allows an attacker on the network to elevate privileges without authentication. The vulnerability exists in DHCP response processing across Windows 10 (versions 1607 and 1809) and Windows Server (2016, 2019, 2022, 2025). Exploitation is assessed as less likely but requires network access to DHCP traffic.
What this means
What could happen
An attacker on the network can exploit the Windows DHCP client to gain administrative privileges on your servers or workstations without using valid credentials, potentially taking full control of the system.
Who's at risk
Windows Server 2016, 2019, 2022, and 2025 administrators, as well as those managing Windows 10 on engineering workstations and HMIs. This affects any system relying on DHCP for IP configuration in networked plants or control centers.
How it could be exploited
An attacker sends a specially crafted DHCP response to a Windows machine on the network. The DHCP client processes this response and an integer underflow occurs in memory, allowing the attacker to execute code with higher privileges. No user interaction is required.
Prerequisites
- Network access to DHCP traffic on the target subnet (ability to intercept or respond to DHCP requests)
- Target system running an affected Windows version
remotely exploitableno authentication requiredlow complexity
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDIf immediate patching is not possible, isolate affected systems from untrusted networks until patches can be deployed
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the July 2026 Microsoft Windows security update to all Windows 10 and Windows Server systems
Long-term hardening
0/1HARDENINGImplement network segmentation to restrict DHCP traffic to authorized servers and subnets
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/17ed1a36-7e56-44e3-9cde-6e943eb38838Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.