Windows DHCP Server Elevation of Privilege Vulnerability
MonitorCVSS 6.8CVE-2026-69415Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionRequired
Summary
Missing authentication for a critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network. The vulnerability requires high privilege credentials and user interaction to exploit.
What this means
What could happen
An attacker with high privileges on a Windows server running DHCP could elevate their access level, potentially gaining control of the DHCP service and the network's IP address allocation, affecting all connected devices including plant control systems.
Who's at risk
Windows Server administrators responsible for DHCP services, particularly in utility environments where DHCP assigns IP addresses to field devices, PLCs, and HMI systems. Affects Windows Server 2016, 2019, 2022, 2025 and Windows 10 systems running DHCP Server roles.
How it could be exploited
An attacker with high-level credentials on a Windows Server with DHCP enabled would craft a network request to an unauthenticated critical function in the DHCP Server service. The attack requires user interaction and results in privilege escalation, giving the attacker elevated control over the DHCP server.
Prerequisites
- High-privilege (administrator-level) credentials on the Windows server
- Windows DHCP Server service must be running
- User interaction required to trigger the vulnerable function
- Network access to the DHCP server
Privilege escalation potentialRequires high-level credentialsUser interaction requiredLow exploit probability (0.7%)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Sep security update to all affected Windows Server and Windows 10 systems running DHCP Server
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/08a54258-5990-48ae-bd18-7b9a8d0bc684Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.