CVE-2019-0785Out-of-bounds Write in Microsoft Windows Server

Severity
9.8CRITICALNVD
EPSS
51.5%
top 2.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages8 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-9fc3-q27f-j286: A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server2022-05-24

📋Vendor Advisories

2
Microsoft
Windows DHCP Server Remote Code Execution Vulnerability2019-07-09
Red Hat
struts2: forced double OGNL evaluation on raw input in tag attributes2016-04-13

🕵️Threat Intelligence

5
Krebs
Patch Tuesday Lowdown, July 2019 Edition2019-07-13
Qualys
July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns | Qualys2019-07-09
Qualys
July 2019 Patch Tuesday – 77 Vulns, 15 Critical, DHCP RCE, Exploited PrivEsc, SQL, Adobe Vulns2019-07-09
Tenable
Microsoft’s July 2019 Patch Tuesday: What You Need to Know2019-07-09
Krebs
Patch Tuesday Lowdown, July 2019 Edition2019-07-09

💬Community

1
Bugzilla
CVE-2016-0785 struts2: forced double OGNL evaluation on raw input in tag attributes2016-04-13
CVE-2019-0785 — Out-of-bounds Write in Microsoft | cvebase