Vulnerability record · CVE-2011-0997 · published 8 April 2011
CVE-2011-0997: ISC DHCP dhclient command injection via DHCP hostname
Isc · Dhcp
dhclient in ISC DHCP 3.0.x through 4.2.x (before 4.2.1-P1), 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 fails to validate the hostname option in DHCP messages before passing it to dhclient-script. Shell metacharacters in that hostname are executed as commands, so a rogue or compromised DHCP server can run arbitrary code on the client as it obtains a lease.
Description
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated command execution with a very high EPSS score, though no confirmed in-the-wild exploitation or KEV listing is recorded.
What it is
dhclient in ISC DHCP 3.0.x through 4.2.x (before 4.2.1-P1), 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 fails to validate the hostname option in DHCP messages before passing it to dhclient-script. Shell metacharacters in that hostname are executed as commands, so a rogue or compromised DHCP server can run arbitrary code on the client as it obtains a lease.
Impact
An attacker controlling DHCP responses gains arbitrary command execution on the requesting host, typically with the privileges dhclient-script runs under (often root), allowing full system compromise.
Attack surface
Reached over the network via a crafted DHCP message; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. The victim must accept a lease from the malicious server, which happens automatically on many clients, so no deliberate user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.84292, 99.68th percentile), indicating strong predicted exploitation activity; reference tags are advisory and vendor errata only, with no public exploit tag supplied.
What to do
- Upgrade ISC DHCP to 4.2.1-P1, 3.1-ESV-R1, 4.1-ESV-R2 or later, or apply the vendor patch from your distribution (Debian DSA-2216/2217, Ubuntu USN-1108-1, Red Hat RHSA-2011-0428/0840).
- If patching is delayed, restrict dhclient to trusted DHCP servers or use static addressing on sensitive hosts.
- Segment untrusted networks so rogue DHCP servers cannot reach clients, and enable DHCP snooping on managed switches.
- Audit dhclient-script and any local customizations for unsafe handling of hostname and other DHCP-supplied values.
- Monitor for unexpected DHCP server addresses or lease parameters on client subnets.
Detection
- Search dhclient-script logs and shell history for command fragments or metacharacters originating from DHCP hostname values.
- Alert on DHCP ACK/OFFER packets whose hostname option contains shell metacharacters (;, |, $, backticks, newlines).
- Monitor for unexpected child processes or outbound connections spawned by dhclient or dhclient-script.
- Track rogue DHCP servers via switch DHCP snooping logs and compare offered server identifiers against the authorized list.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0997 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0997), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.