← Back to browse · API

CVE-2019-0736

Severity
CRITICAL
CVSS
9.8
EPSS
0.03968
Risk score
40.59
CISA KEV
No
PoC
No
Published
2019-08-14
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2019-1496, GHSA-P5W8-9JHP-RCCP
Products
Microsoft:Windows 10 Version 1507 10.0.0 <publication, Microsoft:Windows 10 Version 1607 10.0.0 <publication, Microsoft:Windows 10 Version 1703 10.0.0 <publication, Microsoft:Windows 10 Version 1709 10.0.0 <publication, Microsoft:Windows 10 Version 1709 for 32-bit Systems 10.0.0 <publication, Microsoft:Windows 10 Version 1803 10.0.0 <publication, Microsoft:Windows 7 6.1.0 <publication, Microsoft:Windows 7 Service Pack 1 6.1.0 <publication, Microsoft:Windows 8.1 6.3.0 <publication, Microsoft:Windows Server 2008 Service Pack 2 6.0.0 <publication, Microsoft:Windows Server 2008 R2 Service Pack 1 (Server Core installation) 6.0.0 <publication, Microsoft:Windows Server 2008 R2 Service Pack 1 6.1.0 <publication, Microsoft:Windows Server 2008 R2 Systems Service Pack 1 6.1.0 <publication, Microsoft:Windows Server 2008 Service Pack 2 (Server Core installation) 6.0.0 <publication, Microsoft:Windows Server 2008 Service Pack 2 6.0.0 <publication, Microsoft:Windows Server 2012 (Server Core installation) 6.2.0 <publication, Microsoft:Windows Server 2012 6.2.0 <publication, Microsoft:Windows Server 2012 R2 (Server Core installation) 6.3.0 <publication, Microsoft:Windows Server 2012 R2 6.3.0 <publication, Microsoft:Windows Server 2016 (Server Core installation) 10.0.0 <publication, Microsoft:Windows Server 2016 10.0.0 <publication, Microsoft:Windows Server, version 1803 (Server Core Installation) 10.0.0 <publication
Sources
euvd EUVD-2019-1496

Description

A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vulnerability, an attacker could send specially crafted DHCP responses to a client. The security update addresses the vulnerability by correcting how Windows DHCP clients handle certain DHCP responses.

References