Windows DHCP Server Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62803Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A flaw in Windows DHCP Server allows an authorized local attacker to escalate privileges from a standard user account to SYSTEM level through improper link resolution (link following) before file access. An attacker with local access could craft a malicious symbolic or hard link in a directory accessed by the DHCP Server service; when the service processes the link without proper validation, it executes code with elevated privileges. This affects Windows 10 versions 1607 and 1809, and Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker with local access to a Windows server running DHCP could exploit a link-following flaw to escalate privileges to system level, potentially gaining control of the entire server and the DHCP services that manage your network device assignments.
Who's at risk
IT and OT teams managing Windows-based DHCP servers in your network infrastructure. This affects Windows 10 and Windows Server 2016, 2019, 2022, and 2025 systems that operate DHCP services for IP address assignment and network device management.
How it could be exploited
An authorized local attacker with standard user privileges could craft a malicious file link in the DHCP server's working directory. When the DHCP Server service processes files, it follows the link without proper validation and executes code with SYSTEM privileges, allowing privilege escalation.
Prerequisites
  • Local access to the Windows server (physical or via remote desktop/SSH)
  • Ability to write files to a directory accessible by the DHCP Server service
  • Standard user or low-privilege account credentials
Affects DHCP services (critical network infrastructure)Requires local access (lower risk for remote-only attacks)Low complexity exploitationRequires valid user credentials
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/8
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9418 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9115 or later
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) to Build 10.0.14393.9418 or later
Long-term hardening
0/2
HARDENINGRestrict local user access to servers running DHCP services to authorized administrators only
HARDENINGMonitor DHCP Server service logs for suspicious file activity and privilege escalation attempts
API: /api/v1/advisories/68e83cff-0460-4555-9470-dfe4c8a26bac

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.