Windows DHCP Server Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62761Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A link-following vulnerability in Windows DHCP Server allows an authorized local user to elevate privileges to SYSTEM level through improper file access handling. The vulnerability affects Windows 10 versions 1607 and 1809, and Windows Server 2016, 2019, 2022, and 2025. An attacker with local account access could create a symbolic link that the DHCP Server process would follow during file operations, potentially granting access to protected system files and full system control. Microsoft has released patches for all affected versions and rates exploitation as less likely.

What this means
What could happen
A user with local access to a Windows Server running DHCP services could exploit a link-following flaw to gain system-level privileges, potentially allowing them to modify network configuration, intercept traffic, or disrupt DHCP service availability for connected devices.
Who's at risk
Organizations running Windows Server (2016, 2019, 2022, or 2025) or Windows 10 with DHCP Server role enabled should prioritize this patch. Water utilities, electric cooperatives, and other critical infrastructure using Windows-based DHCP servers are affected. This is most relevant if your network relies on on-premises DHCP rather than cloud-based services.
How it could be exploited
An attacker with local account access could create a symbolic link in a location where the DHCP Server process writes files. When the DHCP service follows the link during file operations, it could write to or read from protected system files with elevated privileges. This allows privilege escalation from user-level to SYSTEM.
Prerequisites
  • Local user account on the Windows Server running DHCP
  • Ability to create files or directories in a location accessible to DHCP Server process
  • DHCP Server role must be installed and running
Requires local access (lower remote risk)Requires existing user credentials (not zero-auth)Privilege escalation to SYSTEM levelAffects DHCP infrastructure which is foundational to network operationLow exploit probability (0.4% EPSS)
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/7
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit) to Build 10.0.17763.9115 or later
HOTFIXUpdate Windows 10 Version 1809 (x64) to Build 10.0.17763.9115 or later
Long-term hardening
0/2
HARDENINGRestrict local account access on DHCP servers to only necessary administrative staff
HARDENINGImplement file system monitoring or integrity checking on DHCP server system directories
API: /api/v1/advisories/f190834b-3665-4392-850c-d7be6bf25a5e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.