Windows DHCP Server Elevation of Privilege Vulnerability
A link-following vulnerability in Windows DHCP Server allows an authorized local user to elevate privileges to SYSTEM level through improper file access handling. The vulnerability affects Windows 10 versions 1607 and 1809, and Windows Server 2016, 2019, 2022, and 2025. An attacker with local account access could create a symbolic link that the DHCP Server process would follow during file operations, potentially granting access to protected system files and full system control. Microsoft has released patches for all affected versions and rates exploitation as less likely.
- Local user account on the Windows Server running DHCP
- Ability to create files or directories in a location accessible to DHCP Server process
- DHCP Server role must be installed and running
Patching may require device reboot — plan for process interruption
/api/v1/advisories/f190834b-3665-4392-850c-d7be6bf25a5eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.