Windows DHCP Server Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-62812Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A flaw in Windows DHCP Server's handling of file access paths (symbolic link following) allows a local user to escalate their privileges to SYSTEM level. An authorized user with a local account on the server can exploit improper link resolution in the DHCP service to gain elevated privileges. This affects Windows Server 2016, 2019, 2022, 2025, and Windows 10. All affected versions have vendor fixes available.
What this means
What could happen
An attacker with local access to a server running Windows DHCP could exploit a flaw in how the DHCP service handles symbolic links to escalate their privileges to system level, potentially allowing them to take control of the entire server and any networks it manages.
Who's at risk
Water utilities and electric utilities that run Windows Server for DHCP services should prioritize patching. This applies to any organization using Windows Server 2016, 2019, 2022, or 2025 as DHCP servers, as well as Windows 10 systems that may run DHCP relay or similar network services. The vulnerability requires local access, so it is most relevant in organizations with a distributed IT infrastructure or contract staff with server access.
How it could be exploited
An attacker with a local user account on the Windows server (such as a help desk user or contractor with logon rights) could create a symbolic link in a directory the DHCP service accesses during its normal operation. When the DHCP service processes files or paths, it follows the link without proper validation, allowing the attacker to read or write files with SYSTEM privileges. This could be leveraged to modify DHCP configurations, inject malicious code into the service, or gain system-level access.
Prerequisites
- Local user account on the Windows server
- DHCP Server service installed and running
- Write access to directories where DHCP service processes files
Local privilege escalationLow complexity exploitationAffects DHCP servers critical to network infrastructureAffects multiple Windows Server versions
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply the August 2026 security update to Windows Server 2019, Windows Server 2022, Windows Server 2025, Windows 10, or Windows Server 2016 as applicable to your environment
Long-term hardening
0/2HARDENINGRestrict local logon access to Windows servers running DHCP to only authorized administrators and necessary service accounts
HARDENINGImplement file system auditing on DHCP-related directories to detect creation of suspicious symbolic links
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f1febee9-4a04-4f0d-b086-ebcf205b59eaGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.