CVE-2019-1213CriticalCVSS 9.8
Windows DHCP Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server. An attacker who successfully exploited the vulnerability could run arbitrary code on the DHCP server. To exploit the vulnerability, an attacker could send a specially crafted packet to a DHCP server. The security update addresses the vulnerability by correcting how DHCP servers handle network packets.
🎯 Affected products5
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for Itanium-Based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
✅ Remediation
KB4512476 (Monthly Rollup) KB4512491 (Security Only)
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1213
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4512476
- referencehttps://support.microsoft.com/help/4512476
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4512491
- referencehttps://support.microsoft.com/help/4512491