peter bassill · operator
$ cve CVE-2006-2372 JSON

CVE-2006-2372 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 90.2% (pctl 100)

Patch early

A public exploit exists.

Description

Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS90.23% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2006-07-11
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftdhcp client service

Public exploits

SourceTitleDate
exploit-dbMicrosoft Windows - DHCP Client Broadcast (MS06-036)2006-07-21

References

→ the Explorer  ·  watch your stack  ·  NVD