Impact
The flaw arises from improper handling of symbolic links in Windows DHCP Server before file access, allowing an authorized local user to bypass normal privilege checks. This leads to higher process privileges, creating a foothold for further attacks. The issue is classified as CWE‑59.
Affected Systems
Microsoft Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012, Windows Server 2012 (Server Core), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core), Windows Server 2016, Windows Server 2016 (Server Core), Windows Server 2019, Windows Server 2019 (Server Core), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core) – all versions running the DHCP Server role are impacted.
Risk and Exploitability
The CVSS base score is 7.8, indicating high‑severity risk. No EPSS data is available, but the vulnerability remains unlisted in the KEV catalog. The attack path requires legitimate local privileges and the ability to send crafted DHCP packets that force the server to follow malicious links. Once executed, the attacker can raise process privileges on the host.
OpenCVE Enrichment