Windows DHCP Server Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-62776Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized local attacker to elevate privileges. An attacker with local user access on a Windows DHCP server could exploit this flaw to gain higher privileges on that machine.
What this means
What could happen
A user with local access to a Windows DHCP server could gain administrator-level privileges on that machine, potentially allowing them to alter DHCP settings, disable the service, or modify network configuration for all connected devices on your network.
Who's at risk
Windows Server administrators and IT operators running DHCP services on Windows Server 2016, 2019, 2022, or 2025 need to patch these systems. This primarily affects IT infrastructure supporting network operations in utilities and municipalities running on-premises DHCP infrastructure.
How it could be exploited
An attacker with a local user account on the DHCP server exploits improper link resolution in the DHCP service to escalate from user to administrator privileges. The attack requires local code execution capability—typically via a compromised account or physical access to the server.
Prerequisites
- Local user account on the Windows DHCP server
- Ability to execute code or interact with the file system as the unprivileged user
Requires local user access (not remotely exploitable without prior compromise)Low complexity exploitationAffects authentication and network infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/6
Do now
0/1HARDENINGRestrict local console and RDP access to DHCP servers to authorized administrators only
Schedule — requires maintenance window
0/5Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9418 or later
All products
HOTFIXUpdate Windows 10 Version 1809 to Build 10.0.17763.9115 or later if running on DHCP server roles
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/823db11f-3c96-41a4-891e-2c3fa5f20a22Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.