peter bassill · operator
$ cve CVE-2004-0894 JSON

CVE-2004-0894 EXPLOIT

7.2
HIGH · CVSS 2.0 · EPSS 3.4% (pctl 89)

Patch early

A public exploit exists.

Description

LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.

Scoring

CVSS7.2 (HIGH, v2.0)
VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS3.41% — more likely to be exploited than 89% of all CVEs
On CISA KEVno
Public exploityes
Published2005-01-10
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD