Windows DHCP Server Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62807Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A link-following vulnerability in Windows DHCP Server allows an authorized local user to elevate privileges to administrative level. The flaw exists in how the DHCP Server process handles file access when it resolves file paths—it does not properly validate symbolic links before following them. An attacker with standard user privileges on the server can create a malicious symbolic link pointing to a sensitive system file, and when the DHCP service writes to that location, the attacker gains the ability to modify files with administrative rights. This affects Windows 10 versions 1607 and 1809, Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
A local user with standard privileges on a Windows server running DHCP could exploit a file link-following flaw to gain administrative rights, potentially allowing them to modify DHCP configurations, redirect network traffic, or disrupt IP address assignment across your facility network.
Who's at risk
Water authorities and utilities operating Windows-based DHCP servers for IP address management in network infrastructure. Particularly relevant if standard-privilege user accounts (engineering workstations, contractor accounts, or service accounts) have local access to DHCP servers. Small to mid-size facilities using Windows Server 2016, 2019, 2022, or 2025 as domain controllers or dedicated DHCP servers.
How it could be exploited
An attacker with a local account on a Windows DHCP Server creates a malicious symbolic link in a location where the DHCP service writes files. When the DHCP Server process (running with elevated privileges) follows the link without proper validation, the attacker can write arbitrary files with administrative privileges, achieving privilege escalation.
Prerequisites
  • Local user account (non-administrative) on the Windows DHCP Server
  • Ability to create files and symbolic links on the server filesystem
  • DHCP Server role enabled and running on the Windows system
Requires local account accessLow complexity exploitationAffects network infrastructure (DHCP)Vendor patches available
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5499
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the August 2026 security update (or later) to all Windows Server and Windows 10 systems running DHCP Server
HARDENINGReview and audit user accounts with local access to DHCP Servers; remove unnecessary accounts
Long-term hardening
0/1
HARDENINGRestrict local login and interactive access to Windows DHCP Servers to authorized personnel only
API: /api/v1/advisories/04677b06-ab9d-4283-b301-22f15484b467

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows DHCP Server Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse