Impact
Improper link resolution before file access (link following) in Windows DHCP Server allows an authorized attacker to elevate privileges locally, potentially gaining higher level privileges on the host which can lead to system compromise or misuse of administrative functions.
Affected Systems
Microsoft Windows 10 Version 1607 and 1809, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 including Server Core installations are affected by this flaw.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity, but no EPSS score is available, and the vulnerability has not been listed in the CISA KEV catalog. Based on the description, the likely attack vector requires an attacker who already has authorized or local access to the DHCP Server; exploitation does not appear to require remote network connectivity or additional privilege escalation steps beyond gaining immediate local control of the DHCP service.
OpenCVE Enrichment