CVE-2019-0547
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 71.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 71.36% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- microsoft/windows 10
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/106394Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0547Patch, Vendor Advisory
- http://www.securityfocus.com/bid/106394Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0547Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.