nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-0785 CVE-2019-0785
CRITICAL
Record summary
CVE-2019-0785 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC.
Description
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Windows ServerBrowse Microsoft / Windows Server | CVE List | 2012 | affected |
| 2012 (Core installation) | affected | ||
| 2012 R2 | affected | ||
| 2012 R2 (Core installation) | affected | ||
| 2016 | affected | ||
| 2016 (Core installation) | affected | ||
| version 1803 (Core Installation) | affected | ||
| 2019 | affected | ||
| 2019 (Core installation) | affected | ||
Windows Server, version 1903 (Server Core installation)Browse Microsoft / Windows Server, version 1903 (Server Core installation) | CVE List | Version range not supplied | affected |
Proofs of concept
1Repository PoCs
GitHubJaky5155/CVE-2019-0785Repository PoCby Jaky5155Stars: 0Not analyzed1 file
References
2portal.msrc.microsoft.com
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0785