Windows DHCP Client Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62755Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A stack-based buffer overflow in the Windows DHCP Client allows an authorized local user to elevate privileges. The vulnerability is in how the DHCP Client processes malformed DHCP response packets, enabling memory corruption that can lead to code execution with administrative rights. Exploitation is assessed as less likely by Microsoft.

What this means
What could happen
A local user with standard privileges could exploit a buffer overflow in the Windows DHCP Client to gain elevated (administrative) privileges on the affected system, potentially allowing them to alter system configuration, install malware, or disrupt services.
Who's at risk
This vulnerability affects Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 (versions 1607, 1809, 21H2, 22H2) and Windows 11 (versions 23H2, 24H2, 25H2, 26H1). It concerns any organization running these systems where standard users need local access. Industrial sites using Windows-based SCADA client stations, historian servers, or engineering workstations are potentially affected if they run vulnerable Windows versions.
How it could be exploited
An attacker with local user access can trigger a stack-based buffer overflow in the Windows DHCP Client component by sending a specially crafted DHCP response packet on the local network. This overwrites memory and allows the attacker to execute arbitrary code with elevated privileges.
Prerequisites
  • Local user account on the affected Windows system
  • Network access to send DHCP traffic on the local network segment
  • DHCP Client service must be enabled and running
Requires local user privilegeNo authentication bypass—attacker must already have local accessAffects widely deployed Windows versionsLow complexity exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Aug security update for your Windows version (Build 10.0.17763.9115 for Server 2019/Win10 1809; Build 10.0.20348.5499 for Server 2022; Build 10.0.19044.7663 for Win10 21H2; Build 10.0.19045.7663 for Win10 22H2; Build 10.0.26100.33296 for Server 2025; Build 10.0.26200.9168 for Win11 25H2/23H2; Build 10.0.22631.7517 for Win11 23H2; Build 10.0.26100.9168 for Win11 24H2; Build 10.0.28000.2704 for Win11 26H1; Build 10.0.14393.9418 for Win10/Server 2016 1607)
API: /api/v1/advisories/cc701c75-db1a-4398-82dc-f662aafa576b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Client Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse