← Vulnerability feed

Vulnerability record · CVE-2006-2372 · published 11 July 2006

CVE-2006-2372: Microsoft Windows DHCP Client Service buffer overflow

Microsoft · Dhcp Client Service

The DHCP Client service in Windows 2000 SP4, XP SP1/SP2, and Server 2003 up to SP1 contains a buffer overflow triggered by a crafted DHCP response. A remote attacker on the same network segment can send a malicious DHCP reply to a client and potentially execute arbitrary code with the privileges of the service. The flaw is remotely reachable without authentication and has a CVSS v2 base score of 10.0.

10.0 CVSS 2.0 High EPSS 90% · top 0.2% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS v2 base score of 10.0 with network reachability, no authentication, full code execution impact, and very high EPSS despite the absence of KEV listing.

What it is

The DHCP Client service in Windows 2000 SP4, XP SP1/SP2, and Server 2003 up to SP1 contains a buffer overflow triggered by a crafted DHCP response. A remote attacker on the same network segment can send a malicious DHCP reply to a client and potentially execute arbitrary code with the privileges of the service. The flaw is remotely reachable without authentication and has a CVSS v2 base score of 10.0.

Impact

Successful exploitation allows arbitrary code execution on the affected host, giving the attacker full control of the system. Because the DHCP Client service runs with high privileges, compromise can lead to complete loss of confidentiality, integrity, and availability.

Attack surface

Reached over the network via a crafted DHCP response delivered to a Windows client running the vulnerable DHCP Client service. No authentication or user interaction is required; the attacker only needs to be positioned to answer or spoof DHCP traffic on the client's network.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.90233, 99.79th percentile) and a public Exploit-DB entry (2054) exists, indicating mature public exploit code.

What to do

  • Apply the Microsoft security update MS06-036 for the affected Windows versions.
  • Upgrade or retire Windows 2000 SP4, XP SP1/SP2, and Server 2003 up to SP1, which are out of support.
  • Disable the DHCP Client service on hosts that use static IP configuration.
  • Segment networks and restrict rogue or spoofed DHCP servers using DHCP snooping and port security.
  • Monitor vendor advisories for any updated guidance on these legacy platforms.

Detection

  • Monitor DHCP server and client logs for malformed or unusually large DHCP responses.
  • Use IDS/IPS signatures for DHCP response buffer overflow patterns targeting the Windows DHCP Client service.
  • Alert on unexpected crashes or restarts of the DHCP Client service (dhcpcsvc) on affected hosts.
  • Hunt for anomalous outbound connections or process creation originating from the DHCP Client service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0222.html
http://secunia.com/advisories/21010 PatchVendor Advisory
http://securityreason.com/securityalert/1201
http://securitytracker.com/id?1016468
http://www.cybsec.com/vuln/CYBSEC-Security_Pre-Advisory_Microsoft_Windows_DHCP_Client_Service_Remote_Buffer_Overflow.pdf Patch
http://www.kb.cert.org/vuls/id/257164 US Government Resource
http://www.osvdb.org/27151
http://www.securityfocus.com/archive/1/439675/100/0/threaded
http://www.securityfocus.com/archive/1/444631/100/0/threaded
http://www.securityfocus.com/bid/18923 Patch
http://www.us-cert.gov/cas/techalerts/TA06-192A.html US Government Resource
http://www.vupen.com/english/advisories/2006/2754
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-036
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A232
https://www.exploit-db.com/exploits/2054
http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0222.html
http://secunia.com/advisories/21010 PatchVendor Advisory
http://securityreason.com/securityalert/1201
http://securitytracker.com/id?1016468
http://www.cybsec.com/vuln/CYBSEC-Security_Pre-Advisory_Microsoft_Windows_DHCP_Client_Service_Remote_Buffer_Overflow.pdf Patch
http://www.kb.cert.org/vuls/id/257164 US Government Resource
http://www.osvdb.org/27151
http://www.securityfocus.com/archive/1/439675/100/0/threaded
http://www.securityfocus.com/archive/1/444631/100/0/threaded
http://www.securityfocus.com/bid/18923 Patch
http://www.us-cert.gov/cas/techalerts/TA06-192A.html US Government Resource
http://www.vupen.com/english/advisories/2006/2754
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-036
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A232
https://www.exploit-db.com/exploits/2054

Track CVE-2006-2372 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed7.8CVE-2026-20700Apple OS memory corruption allows arbitrary code executionA memory corruption flaw caused by improper state management affects iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Apple states it is aware of a re…KEVEPSS 1.3%analysed8.8CVE-2025-14174Google Chrome ANGLE out-of-bounds memory access on MacChrome on macOS before 143.0.7499.110 contains an out-of-bounds memory access in the ANGLE graphics layer, classified as an out-of-bounds write (CWE-…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2006-2372), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.