Vulnerability record · CVE-2006-2372 · published 11 July 2006
CVE-2006-2372: Microsoft Windows DHCP Client Service buffer overflow
Microsoft · Dhcp Client Service
The DHCP Client service in Windows 2000 SP4, XP SP1/SP2, and Server 2003 up to SP1 contains a buffer overflow triggered by a crafted DHCP response. A remote attacker on the same network segment can send a malicious DHCP reply to a client and potentially execute arbitrary code with the privileges of the service. The flaw is remotely reachable without authentication and has a CVSS v2 base score of 10.0.
Description
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS v2 base score of 10.0 with network reachability, no authentication, full code execution impact, and very high EPSS despite the absence of KEV listing.
What it is
The DHCP Client service in Windows 2000 SP4, XP SP1/SP2, and Server 2003 up to SP1 contains a buffer overflow triggered by a crafted DHCP response. A remote attacker on the same network segment can send a malicious DHCP reply to a client and potentially execute arbitrary code with the privileges of the service. The flaw is remotely reachable without authentication and has a CVSS v2 base score of 10.0.
Impact
Successful exploitation allows arbitrary code execution on the affected host, giving the attacker full control of the system. Because the DHCP Client service runs with high privileges, compromise can lead to complete loss of confidentiality, integrity, and availability.
Attack surface
Reached over the network via a crafted DHCP response delivered to a Windows client running the vulnerable DHCP Client service. No authentication or user interaction is required; the attacker only needs to be positioned to answer or spoof DHCP traffic on the client's network.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.90233, 99.79th percentile) and a public Exploit-DB entry (2054) exists, indicating mature public exploit code.
What to do
- Apply the Microsoft security update MS06-036 for the affected Windows versions.
- Upgrade or retire Windows 2000 SP4, XP SP1/SP2, and Server 2003 up to SP1, which are out of support.
- Disable the DHCP Client service on hosts that use static IP configuration.
- Segment networks and restrict rogue or spoofed DHCP servers using DHCP snooping and port security.
- Monitor vendor advisories for any updated guidance on these legacy platforms.
Detection
- Monitor DHCP server and client logs for malformed or unusually large DHCP responses.
- Use IDS/IPS signatures for DHCP response buffer overflow patterns targeting the Windows DHCP Client service.
- Alert on unexpected crashes or restarts of the DHCP Client service (dhcpcsvc) on affected hosts.
- Hunt for anomalous outbound connections or process creation originating from the DHCP Client service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-2372 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-2372), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.