Windows DHCP Server Elevation of Privilege Vulnerability
A link-following vulnerability in Windows DHCP Server allows an authorized local user to elevate privileges to administrative level. The flaw exists in how the DHCP Server process handles file access when it resolves file paths—it does not properly validate symbolic links before following them. An attacker with standard user privileges on the server can create a malicious symbolic link pointing to a sensitive system file, and when the DHCP service writes to that location, the attacker gains the ability to modify files with administrative rights. This affects Windows 10 versions 1607 and 1809, Windows Server 2016, 2019, 2022, and 2025.
- Local user account (non-administrative) on the Windows DHCP Server
- Ability to create files and symbolic links on the server filesystem
- DHCP Server role enabled and running on the Windows system
Patching may require device reboot — plan for process interruption
/api/v1/advisories/04677b06-ab9d-4283-b301-22f15484b467Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.