CVE-2019-0736: Microsoft Windows 10
Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vulnerability, an attacker could send specially crafted DHCP responses to a client. The security update addresses the vulnerability by correcting how Windows DHCP clients handle certain DHCP responses.
Affected products
- Microsoft Windows 10: affected versions not specified; version 1607 only; version 1703 only; version 1709 only; version 1803 only
- Microsoft Windows 7: affected versions not specified
- Microsoft Windows 8.1: affected versions not specified
- Microsoft Windows Rt 8.1: affected versions not specified
- Microsoft Windows Server 2008: affected versions not specified; version r2 only
- Microsoft Windows Server 2012: affected versions not specified; version r2 only
- Microsoft Windows Server 2016: affected versions not specified; version 1803 only
Published 2019-08-14. Last modified 2026-06-17.