>> Microsoft Windows DHCP Client Service Command Execution Vulnerability (MS06-036)
Title : Microsoft Windows DHCP Client Service Command Execution Vulnerability (MS06-036) VUPEN ID : VUPEN/ADV-2006-2754 CVE ID : CVE-2006-2372
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-11
Technical Description
A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to take complete control of an affected system. This flaw is due to a buffer overflow error in the DHCP Client service (dhcpcsvc.dll) when handling malformed DHCP responses, which could be exploited by attackers to execute arbitrary commands via a malicious packet.
Note : Attacks are limited to a local subnet in a network configuration scenario where DHCP and BOOTP forwarding are disabled.