← Vulnerability feed

Vulnerability record · CVE-2019-0547 · published 8 January 2019

CVE-2019-0547: Windows DHCP client memory corruption via crafted DHCP responses

Microsoft · Windows 10

The Windows DHCP client has an out-of-bounds write (CWE-787) triggered by specially crafted DHCP responses, described by Microsoft as a remote code execution vulnerability. It affects Windows 10 and Windows 10 Server, and because DHCP is processed automatically, a hostile or spoofed DHCP server can reach the client without any user action.

9.8 CVSS 3.0 Critical EPSS 71% · top 0.6% CWE-787 · Out-of-bounds write
9.8CVSS 3.0 base score, v2 7.5
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCritical CVSS (9.8) with no authentication or user interaction required and a very high EPSS score, though no KEV listing or known public exploit is recorded.

What it is

The Windows DHCP client has an out-of-bounds write (CWE-787) triggered by specially crafted DHCP responses, described by Microsoft as a remote code execution vulnerability. It affects Windows 10 and Windows 10 Server, and because DHCP is processed automatically, a hostile or spoofed DHCP server can reach the client without any user action.

Impact

An attacker who controls or spoofs DHCP responses can corrupt memory in the client and potentially execute code in the context of the DHCP client service, giving them a foothold on the host.

Attack surface

Reached over the network via DHCP response packets to a Windows 10 or Windows 10 Server client; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware use is recorded in this data, but EPSS is very high (0.714, 99.4th percentile), indicating strong predicted exploitation activity.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2019-0547 on all affected Windows 10 and Windows 10 Server systems.
  • Restrict or monitor DHCP traffic on untrusted network segments and use DHCP snooping or port security where available to block rogue DHCP servers.
  • Segment networks so clients do not accept DHCP responses from untrusted or attacker-controlled segments.
  • Track unpatched Windows 10 and Windows 10 Server endpoints and prioritize them for remediation given the high EPSS score.

Detection

  • Monitor for unexpected or anomalous DHCP server activity on the network, including rogue or spoofed DHCP responders.
  • Watch for crashes or abnormal termination of the Windows DHCP client service on endpoints.
  • Correlate endpoint telemetry for suspicious process activity originating from the DHCP client service context.
  • Review DHCP server logs and network flow data for DHCP responses from unauthorized sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-0547 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2015-2426Windows Adobe Type Manager Library buffer underflow via crafted OpenType fontA buffer underflow in atmfd.dll, the Windows Adobe Type Manager Library, lets a crafted OpenType font trigger memory corruption. Because font parsing…KEVEPSS 87%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed10.0CVE-2020-1467Microsoft windows 10 vulnerabilityAn elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability …EPSS 3.5%9.9CVE-2021-26424Windows TCP/IP stack remote code execution flawCVE-2021-26424 is a remote code execution vulnerability in the Windows TCP/IP stack affecting a broad set of Windows client and server releases. Micr…EPSS 61%analysed9.9CVE-2021-28476Microsoft windows 10 vulnerabilityWindows Hyper-V Remote Code Execution VulnerabilityEPSS 39%9.9CVE-2021-26867Microsoft windows 10 vulnerabilityWindows Hyper-V Remote Code Execution VulnerabilityEPSS 2.8%9.9CVE-2019-1384Microsoft windows 10 insufficiently protected credentials vulnerabilityA security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerabi…EPSS 7.6%9.9CVE-2019-1365Microsoft windows 10 vulnerabilityAn elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attac…EPSS 4.4%

Source: NIST National Vulnerability Database (record CVE-2019-0547), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.