peter bassill · operator
$ cve CVE-2004-0567 JSON

CVE-2004-0567 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 68.7% (pctl 99)

Patch early

A public exploit exists.

Description

The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS68.69% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows nt

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD