Vulnerability record · CVE-2019-0698 · published 9 April 2019
CVE-2019-0698: Windows DHCP client out-of-bounds write allows remote code execution
Microsoft · Windows 10
The Windows DHCP client contains an out-of-bounds write (CWE-787) triggered when it processes a specially crafted DHCP response. Because the client parses DHCP replies automatically, a network-adjacent attacker can corrupt memory without any user action. Microsoft rates it critical with a CVSS 3.0 base score of 9.8.
Description
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0697, CVE-2019-0726.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS 9.8 with no authentication or user interaction required, though no confirmed in-the-wild exploitation is recorded.
What it is
The Windows DHCP client contains an out-of-bounds write (CWE-787) triggered when it processes a specially crafted DHCP response. Because the client parses DHCP replies automatically, a network-adjacent attacker can corrupt memory without any user action. Microsoft rates it critical with a CVSS 3.0 base score of 9.8.
Impact
An attacker who successfully triggers the flaw can execute arbitrary code in the context of the DHCP client service, potentially gaining full control of the affected host. The CVSS vector shows high confidentiality, integrity and availability impact.
Attack surface
Reached over the network by sending crafted DHCP responses to a Windows client; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. The attacker must be positioned to deliver DHCP traffic to the target, typically on the same broadcast domain or via a rogue DHCP server.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware association is recorded in the references, which only carry Patch and Vendor Advisory tags. EPSS is high at 0.6285 (99.158th percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.
What to do
- Apply the Microsoft security update for CVE-2019-0698 as soon as possible.
- Disable or restrict the DHCP client service on hosts that do not require dynamic addressing.
- Use DHCP snooping and port security on switches to block rogue DHCP servers and spoofed responses.
- Segment networks so untrusted hosts cannot deliver DHCP traffic to sensitive clients.
- Monitor for anomalous DHCP server behavior on the local segment.
Detection
- Alert on DHCP responses originating from unexpected or unauthorized servers on the network.
- Monitor Windows event logs and crash dumps for faults in the DHCP client service (dhcpcsvc).
- Use network monitoring to flag malformed or unusually large DHCP option payloads.
- Correlate DHCP server inventory against known authorized servers to detect rogue responders.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0698 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0698 | PatchVendor Advisory |
Track CVE-2019-0698 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0698), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.