Windows DHCP Server Elevation of Privilege Vulnerability
A flaw in Windows DHCP Server allows an authorized local attacker to escalate privileges from a standard user account to SYSTEM level through improper link resolution (link following) before file access. An attacker with local access could craft a malicious symbolic or hard link in a directory accessed by the DHCP Server service; when the service processes the link without proper validation, it executes code with elevated privileges. This affects Windows 10 versions 1607 and 1809, and Windows Server 2016, 2019, 2022, and 2025.
- Local access to the Windows server (physical or via remote desktop/SSH)
- Ability to write files to a directory accessible by the DHCP Server service
- Standard user or low-privilege account credentials
Patching may require device reboot — plan for process interruption
/api/v1/advisories/68e83cff-0460-4555-9470-dfe4c8a26bacGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.