Windows DHCP Server Elevation of Privilege Vulnerability

MonitorCVSS 6.8CVE-2026-69415Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionRequired
Summary

Missing authentication for a critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network. The vulnerability requires high privilege credentials and user interaction to exploit.

What this means
What could happen
An attacker with high privileges on a Windows server running DHCP could elevate their access level, potentially gaining control of the DHCP service and the network's IP address allocation, affecting all connected devices including plant control systems.
Who's at risk
Windows Server administrators responsible for DHCP services, particularly in utility environments where DHCP assigns IP addresses to field devices, PLCs, and HMI systems. Affects Windows Server 2016, 2019, 2022, 2025 and Windows 10 systems running DHCP Server roles.
How it could be exploited
An attacker with high-level credentials on a Windows Server with DHCP enabled would craft a network request to an unauthenticated critical function in the DHCP Server service. The attack requires user interaction and results in privilege escalation, giving the attacker elevated control over the DHCP server.
Prerequisites
  • High-privilege (administrator-level) credentials on the Windows server
  • Windows DHCP Server service must be running
  • User interaction required to trigger the vulnerable function
  • Network access to the DHCP server
Privilege escalation potentialRequires high-level credentialsUser interaction requiredLow exploit probability (0.7%)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Sep security update to all affected Windows Server and Windows 10 systems running DHCP Server
API: /api/v1/advisories/08a54258-5990-48ae-bd18-7b9a8d0bc684

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.