Impact
The vulnerability arises from improper link resolution before file access in the Windows DHCP Server. An attacker with sufficient local privileges can exploit this flaw to read or modify files outside the intended scope, effectively elevating their own privileges. The weakness is a classic path‑traversal flaw (CWE‑59) that can compromise the integrity and confidentiality of the operating system.
Affected Systems
Microsoft Windows 10 (Version 1607 and 1809) and Microsoft Windows Server versions 2012 through 2025, including all Server Core installations, are affected. This includes Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025.
Risk and Exploitability
The CVSS score of 7.8 flags this locally‑executed flaw as high severity, and while the EPSS score is not available, the vulnerability is not listed in CISA's KEV catalog, suggesting no widely known exploits yet. An authorized user on the host can exploit the link‑following error to gain elevated local privileges, granting them the ability to modify system files, install malware, or pivot to other systems. Therefore, the risk is significant for systems where privileged users may execute DHCP Server processes without strict controls.
OpenCVE Enrichment