logo

Analysis of a 1day (CVE-2019-0547) and discovery of a forgotten condition in the patch (CVE-2019-0726) – Part 1 of 2

ID: c974f3d0-4f0b-5e5d-a3a0-759a9875189a

STIX ID: report--c974f3d0-4f0b-5e5d-a3a0-759a9875189a

Feed Name: SensePost Blog

Threat Score
55/100

Date Published: 2019-05-02

Date Updated: 2026-04-29

...
...

This write-up analyzes a Windows DHCP client parsing bug: patch diffing of dhcpcore.dll reveals a zero-length HeapAlloc issue in handling DHCP Option 119 (Domain Search Option), leading to a memory corruption vulnerability. The author documents PoCs, describes how the original patch was bypassed to cause denial-of-service, and reported the issue as CVE-2019-0726; no reliable remote code execution is shown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.