Windows DHCP Client Elevation of Privilege Vulnerability

Plan PatchCVSS 7.5CVE-2026-49181Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Integer underflow vulnerability in Windows DHCP Client allows an attacker on the network to elevate privileges without authentication. The vulnerability exists in DHCP response processing across Windows 10 (versions 1607 and 1809) and Windows Server (2016, 2019, 2022, 2025). Exploitation is assessed as less likely but requires network access to DHCP traffic.

What this means
What could happen
An attacker on the network can exploit the Windows DHCP client to gain administrative privileges on your servers or workstations without using valid credentials, potentially taking full control of the system.
Who's at risk
Windows Server 2016, 2019, 2022, and 2025 administrators, as well as those managing Windows 10 on engineering workstations and HMIs. This affects any system relying on DHCP for IP configuration in networked plants or control centers.
How it could be exploited
An attacker sends a specially crafted DHCP response to a Windows machine on the network. The DHCP client processes this response and an integer underflow occurs in memory, allowing the attacker to execute code with higher privileges. No user interaction is required.
Prerequisites
  • Network access to DHCP traffic on the target subnet (ability to intercept or respond to DHCP requests)
  • Target system running an affected Windows version
remotely exploitableno authentication requiredlow complexity
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDIf immediate patching is not possible, isolate affected systems from untrusted networks until patches can be deployed
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Microsoft Windows security update to all Windows 10 and Windows Server systems
Long-term hardening
0/1
HARDENINGImplement network segmentation to restrict DHCP traffic to authorized servers and subnets
API: /api/v1/advisories/17ed1a36-7e56-44e3-9cde-6e943eb38838

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Client Elevation of Privilege Vulnerability | CVSS 7.5 - OTPulse