Vulnerability Intelligence Report
Windows DHCP Server Denial of Service Vulnerability
CVE-2019-1212
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could cause the DHCP server service to stop responding. To exploit the vulnerability, a remote unauthenticated attacker could send a specially crafted packet to an affected DHCP server. The security update addresses the vulnerability by correcting how DHCP servers handle network packets.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:6.74%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Microsoft | Windows 10 Version 1803 | 10.0.0 < publication (affected) |
| Microsoft | Windows Server, version 1803 (Server Core Installation) | 10.0.0 < publication (affected) |
| Microsoft | Windows 10 Version 1809 | 10.0.0 < publication (affected) |
| Microsoft | Windows Server 2019 | 10.0.0 < publication (affected) |
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.0 < publication (affected) |
| Microsoft | Windows 10 Version 1709 for 32-bit Systems | 10.0.0 < publication (affected) |
| Microsoft | Windows 10 Version 1709 | 10.0.0 < publication (affected) |
| Microsoft | Windows 10 Version 1903 for 32-bit Systems | 10.0.0 < publication (affected) |
| Microsoft | Windows 10 Version 1903 for x64-based Systems | 10.0.0 < publication (affected) |
| Microsoft | Windows 10 Version 1903 for ARM64-based Systems | 10.0.0 < publication (affected) |
| Microsoft | Windows Server, version 1903 (Server Core installation) | 10.0.0 < publication (affected) |
| Microsoft | Windows 10 Version 1607 | 10.0.0 < publication (affected) |
| Microsoft | Windows Server 2016 | 10.0.0 < publication (affected) |
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.0 < publication (affected) |
| Microsoft | Windows 7 | 6.1.0 < publication (affected) |
| Microsoft | Windows 7 Service Pack 1 | 6.1.0 < publication (affected) |
| Microsoft | Windows 8.1 | 6.3.0 < publication (affected) |
| Microsoft | Windows Server 2008 Service Pack 2 | 6.0.0 < publication (affected) |
| Microsoft | Windows Server 2008 Service Pack 2 (Server Core installation) | 6.0.0 < publication (affected) |
| Microsoft | Windows Server 2008 Service Pack 2 | 6.0.0 < publication (affected) |
| Microsoft | Windows Server 2008 R2 Systems Service Pack 1 | 6.1.0 < publication (affected) |
| Microsoft | Windows Server 2008 R2 Service Pack 1 | 6.1.0 < publication (affected) |
| Microsoft | Windows Server 2008 R2 Service Pack 1 (Server Core installation) | 6.0.0 < publication (affected) |
| Microsoft | Windows Server 2012 | 6.2.0 < publication (affected) |
| Microsoft | Windows Server 2012 (Server Core installation) | 6.2.0 < publication (affected) |
| Microsoft | Windows Server 2012 R2 | 6.3.0 < publication (affected) |
| Microsoft | Windows Server 2012 R2 (Server Core installation) | 6.3.0 < publication (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
6.738%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Microsoft Corporation · Vendor · USA |
| Reserved | 2018-11-26T00:00:00 |
| Published | 2019-08-14T20:55:05 |
| Patch Date | 2019-08-13 |
| Last Updated | 2024-08-04T18:13:29 |
Community Chatter & Buzz