Critical CVSS 9.8 EPSS 0.04246 2019-08 archive

Executive Summary

A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server. An attacker who successfully exploited the vulnerability could run arbitrary code on the DHCP server. To exploit the vulnerability, an attacker could send a specially crafted packet to a DHCP server. The security update addresses the vulnerability by correcting how DHCP servers handle network packets.

Overview

9.8
CVSS CRITICAL
Critical
MS Severity
Not Exploited
MS Exploit Status
N/A
MS Exploit Likelihood
Category Remote Code Execution
Released Aug 13 2019
Last Updated Aug 13 2019
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.04246 — 0.89759 percentile

CVSS Vector

ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
Temporal Score: 8.8

EPSS Score

0.04246
probability of exploitation in the next 30 days
0.89759 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

5 affected products
Product KB Article Severity Impact Restart Required
Windows Server 2008 for 32-bit Systems Service Pack 2 4512476 (Monthly Rollup) 4512491 (Security Only) Critical Remote Code Execution Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 4512476 (Monthly Rollup) 4512491 (Security Only) Critical Remote Code Execution Yes
Windows Server 2008 for Itanium-Based Systems Service Pack 2 4512476 (Monthly Rollup) 4512491 (Security Only) Critical Remote Code Execution Yes
Windows Server 2008 for x64-based Systems Service Pack 2 4512476 (Monthly Rollup) 4512491 (Security Only) Critical Remote Code Execution Yes
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 4512476 (Monthly Rollup) 4512491 (Security Only) Critical Remote Code Execution Yes

Patches

1 patch
Article Type Restart
4512476 (Monthly Rollup) 4512491 Monthly Rollup Yes

Known Exploits

Acknowledgments

Microsoft Platform Security Assurance & Vulnerability Research