Vulnerability record · CVE-2008-0084 · published 12 February 2008
CVE-2008-0084: Windows Vista TCP/IP DHCP packet denial of service
Microsoft · Windows Vista
An unspecified flaw in the TCP/IP stack of Microsoft Windows Vista lets a remote DHCP server crash the system with a crafted DHCP packet, causing a hang and restart. The vulnerability is remotely reachable without authentication, so any Vista host that accepts DHCP from an untrusted or spoofed server is at risk.
Description
Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet.
AV:N/AC:L/Au:N/C:N/I:N/A:C
Automated analysis
high priorityRemote, unauthenticated denial of service with complete availability impact and very high EPSS, though the affected platform is legacy and no active exploitation is confirmed.
What it is
An unspecified flaw in the TCP/IP stack of Microsoft Windows Vista lets a remote DHCP server crash the system with a crafted DHCP packet, causing a hang and restart. The vulnerability is remotely reachable without authentication, so any Vista host that accepts DHCP from an untrusted or spoofed server is at risk.
Impact
An attacker controlling or spoofing a DHCP server can force a full denial of service on the target Vista machine, interrupting all work and services until it restarts. No confidentiality or integrity impact is described; the effect is availability loss only.
Attack surface
Reached over the network via DHCP traffic (AV:N, AC:L, Au:N), meaning no authentication or user interaction is required. The attacker must be positioned to deliver DHCP responses to the victim, such as on the same broadcast domain or via a rogue DHCP server.
Exploitation
Not listed in CISA KEV and no public exploit tags appear in the references, but EPSS is very high (0.736, 99.4th percentile), indicating elevated predicted exploitation likelihood. The record does not confirm active exploitation.
What to do
- Apply Microsoft security bulletin MS08-004 for Windows Vista as the primary fix.
- Restrict DHCP to trusted servers using DHCP snooping or port security on switches to block rogue DHCP responses.
- Segment or firewall networks so untrusted hosts cannot deliver DHCP replies to Vista clients.
- Retire or isolate unsupported Windows Vista systems that cannot be patched.
Detection
- Monitor Vista hosts for unexpected hangs or restarts correlated with DHCP lease activity.
- Alert on DHCP responses originating from unauthorized or unexpected servers on the local segment.
- Review DHCP server logs and network captures for malformed or anomalous DHCP packets targeting Vista clients.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0084 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0084), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.