Impact
An attacker who has local access to a Windows system running DHCP Server can exploit an improper link resolution before file access, known as ‘link following.’ The flaw permits the server to follow a crafted link that leads it to access files not intended for that operation, thereby allowing the attacker to elevate privileges on the local machine. The vulnerability is classified as CWE‑59 and poses significant risks to confidentiality, integrity, and availability if exploited.
Affected Systems
Microsoft Windows 10 version 1607 and 1809, Microsoft Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, Server 2025, and their Server Core installations are affected.
Risk and Exploitability
The CVSS score of 7.8 rates this as a high‑severity flaw, and the EPSS score is less than 1 %, indicating a very low but non‑zero exploitation probability. The flaw is not listed in the CISA KEV catalog. Attackers must have local or privileged access to the machine and the DHCP Server service must be running; the attack vector is local. Given the high severity and the prerequisite of local access, the risk remains significant for any unpatched system hosting DHCP Server.
OpenCVE Enrichment