Rapid7 Vulnerability & Exploit Database

Microsoft CVE-2019-0736: Windows DHCP Client Remote Code Execution Vulnerability

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Microsoft CVE-2019-0736: Windows DHCP Client Remote Code Execution Vulnerability

Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
08/13/2019
Created
08/14/2019
Added
08/13/2019
Modified
11/18/2021

Description

A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vulnerability, an attacker could send specially crafted DHCP responses to a client. The security update addresses the vulnerability by correcting how Windows DHCP clients handle certain DHCP responses.

Solution(s)

  • msft-kb4512482-5ed85e60-5ce7-4c4c-94aa-f19944914692
  • msft-kb4512482-68a99d81-d48f-4437-9515-ea4a427f4014
  • msft-kb4512482-69a5f449-ad8a-42a5-a815-014c374a7293
  • msft-kb4512486-16bba1d9-7035-4243-b78b-cea3df5096b6
  • msft-kb4512486-2d01b298-6879-4d30-8a68-e872592d343e
  • msft-kb4512486-437934f0-2915-4e74-b1cc-04921ce3aef1
  • msft-kb4512486-cb62a71d-be6d-491e-9e4d-046e3dff67e9
  • msft-kb4512486-d6348d13-661b-4391-b03d-77cbf3143cd2
  • msft-kb4512486-fc466b63-7e33-42b7-8bfe-72335a76bb07
  • msft-kb4512489-90af280c-d27d-450d-a8de-81ca67856fc0
  • msft-kb4512489-b3966674-69a0-477b-a7cf-038bf6d6bf58
  • msft-kb4512489-bfc44f53-1c17-46df-9be6-9009a1a38c70
  • msft-kb4512491-08cff48b-50a6-45e0-80f9-1e9c166f5ebd
  • msft-kb4512491-ba106612-9217-4c05-84e3-bf93da04241b
  • msft-kb4512491-d0f0c55e-5ea3-418c-a858-82f582466388
  • msft-kb4512497-6dbe32fb-5832-4dac-8ec8-31c4b0651e31
  • msft-kb4512497-d8fdba67-9336-4531-bc67-4d7eedc79b4f
  • msft-kb4512501-5570183b-a0b7-4478-b0af-47a6e65417ca
  • msft-kb4512501-d45c0b6d-99f1-4b6e-b7a0-2fbaa7335985
  • msft-kb4512501-e1c03faa-adc1-4068-97c4-089a33cb5add
  • msft-kb4512507-84eb119c-d9c4-487f-b45a-0b8188a2d270
  • msft-kb4512507-a50734e7-f388-46dd-b697-513537829ae3
  • msft-kb4512516-5909e402-b1ec-4dc4-8648-d73a81a115aa
  • msft-kb4512516-646eec92-7205-48d6-9a66-ba080e2824ed
  • msft-kb4512517-081388ab-f979-4aef-93fe-813c0044c838
  • msft-kb4512517-4a96dbb7-bbf9-4813-9bfe-b84b252fcaa7
  • msft-kb4512517-af89cf2e-ce74-4a9e-b16d-070888bce28c

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;