CVE-2026-62812: Windows DHCP Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Other sources
Windows DHCP Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5499Fixed in 10.0.20348.5440Patch KB5120229 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9115Patch KB5120238 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9418Patch KB5120418 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33296Fixed in 10.0.26100.33222Patch KB5120228 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23338Patch KB5120385 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26280Patch KB5120386
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62812?
CVE-2026-62812 has a high severity rating of 7.8.
How do I fix CVE-2026-62812?
To fix CVE-2026-62812, apply the latest security updates provided by Microsoft for affected Windows versions.
What type of vulnerability is CVE-2026-62812?
CVE-2026-62812 is an elevation of privilege vulnerability in the Windows DHCP Server.
Who is affected by CVE-2026-62812?
CVE-2026-62812 affects users of Microsoft Windows 10 and various versions of Windows Server including 2022, 2019, and 2016.
What can an attacker do with CVE-2026-62812?
An authorized attacker can elevate their privileges locally on a system impacted by CVE-2026-62812.