Buffer overflow in Microsoft Windows and Windows Server - CVE-2019-1212

 

Buffer overflow in Microsoft Windows and Windows Server - CVE-2019-1212

Published: August 13, 2019


Vulnerability identifier: #VU20203
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1212
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error the Windows Server DHCP service when processing DHCP packets. A remote attacker can create specially crafted DHCP packets to the affected service, trigger memory corruption and perform denial of service attack.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2019-1212

Install updates from vendor's website.


External References

Related Security Bulletins