Vulnerability record · CVE-2019-0547 · published 8 January 2019
CVE-2019-0547: Windows DHCP client memory corruption via crafted DHCP responses
Microsoft · Windows 10
The Windows DHCP client has an out-of-bounds write (CWE-787) triggered by specially crafted DHCP responses, described by Microsoft as a remote code execution vulnerability. It affects Windows 10 and Windows 10 Server, and because DHCP is processed automatically, a hostile or spoofed DHCP server can reach the client without any user action.
Description
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS (9.8) with no authentication or user interaction required and a very high EPSS score, though no KEV listing or known public exploit is recorded.
What it is
The Windows DHCP client has an out-of-bounds write (CWE-787) triggered by specially crafted DHCP responses, described by Microsoft as a remote code execution vulnerability. It affects Windows 10 and Windows 10 Server, and because DHCP is processed automatically, a hostile or spoofed DHCP server can reach the client without any user action.
Impact
An attacker who controls or spoofs DHCP responses can corrupt memory in the client and potentially execute code in the context of the DHCP client service, giving them a foothold on the host.
Attack surface
Reached over the network via DHCP response packets to a Windows 10 or Windows 10 Server client; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is recorded in this data, but EPSS is very high (0.714, 99.4th percentile), indicating strong predicted exploitation activity.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2019-0547 on all affected Windows 10 and Windows 10 Server systems.
- Restrict or monitor DHCP traffic on untrusted network segments and use DHCP snooping or port security where available to block rogue DHCP servers.
- Segment networks so clients do not accept DHCP responses from untrusted or attacker-controlled segments.
- Track unpatched Windows 10 and Windows 10 Server endpoints and prioritize them for remediation given the high EPSS score.
Detection
- Monitor for unexpected or anomalous DHCP server activity on the network, including rogue or spoofed DHCP responders.
- Watch for crashes or abnormal termination of the Windows DHCP client service on endpoints.
- Correlate endpoint telemetry for suspicious process activity originating from the DHCP client service context.
- Review DHCP server logs and network flow data for DHCP responses from unauthorized sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/106394 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0547 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/106394 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0547 | PatchVendor Advisory |
Track CVE-2019-0547 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0547), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.