Vulnerability record · CVE-2019-0785 · published 15 July 2019
CVE-2019-0785: Windows Server DHCP failover memory corruption RCE
Microsoft · Windows Server 2012
The Windows Server DHCP service contains an out-of-bounds write (CWE-787) that corrupts memory when specially crafted packets are sent to a DHCP failover server. Because the flaw is reachable over the network without authentication, it can lead to remote code execution on the affected server. It matters because DHCP servers are typically unauthenticated infrastructure endpoints, so exposure is broad wherever failover is enabled.
Description
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and high EPSS make this a critical patching priority despite no KEV listing.
What it is
The Windows Server DHCP service contains an out-of-bounds write (CWE-787) that corrupts memory when specially crafted packets are sent to a DHCP failover server. Because the flaw is reachable over the network without authentication, it can lead to remote code execution on the affected server. It matters because DHCP servers are typically unauthenticated infrastructure endpoints, so exposure is broad wherever failover is enabled.
Impact
An unauthenticated attacker can corrupt memory in the DHCP service and potentially execute arbitrary code in the service context, giving full control of the server. Successful exploitation could also cause a service crash or denial of service.
Attack surface
Reached over the network by sending crafted packets to a DHCP failover server; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is required. Only systems running the DHCP server role with failover configured are in scope.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is recorded in the references, but EPSS is high at roughly 0.50 (98.8th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the Microsoft security update for CVE-2019-0785 as the first action.
- If DHCP failover is not required, disable the failover configuration or the DHCP server role on exposed hosts.
- Restrict network access to DHCP failover traffic so only trusted partner servers can reach the service.
- Monitor and segment DHCP servers from untrusted network segments to reduce reachable attack paths.
Detection
- Monitor DHCP server service crashes or unexpected restarts on failover-enabled hosts.
- Inspect network traffic to DHCP failover ports for malformed or anomalous packets from unexpected sources.
- Correlate DHCP service process crashes with subsequent suspicious process creation on the same host.
- Review Windows event logs for DHCP server errors and unusual service termination events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0785 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0785 | PatchVendor Advisory |
Track CVE-2019-0785 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0785), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.