Windows DHCP Server Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62776Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized local attacker to elevate privileges. An attacker with local user access on a Windows DHCP server could exploit this flaw to gain higher privileges on that machine.

What this means
What could happen
A user with local access to a Windows DHCP server could gain administrator-level privileges on that machine, potentially allowing them to alter DHCP settings, disable the service, or modify network configuration for all connected devices on your network.
Who's at risk
Windows Server administrators and IT operators running DHCP services on Windows Server 2016, 2019, 2022, or 2025 need to patch these systems. This primarily affects IT infrastructure supporting network operations in utilities and municipalities running on-premises DHCP infrastructure.
How it could be exploited
An attacker with a local user account on the DHCP server exploits improper link resolution in the DHCP service to escalate from user to administrator privileges. The attack requires local code execution capability—typically via a compromised account or physical access to the server.
Prerequisites
  • Local user account on the Windows DHCP server
  • Ability to execute code or interact with the file system as the unprivileged user
Requires local user access (not remotely exploitable without prior compromise)Low complexity exploitationAffects authentication and network infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/6
Do now
0/1
HARDENINGRestrict local console and RDP access to DHCP servers to authorized administrators only
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9418 or later
All products
HOTFIXUpdate Windows 10 Version 1809 to Build 10.0.17763.9115 or later if running on DHCP server roles
API: /api/v1/advisories/823db11f-3c96-41a4-891e-2c3fa5f20a22

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse