CVE-2004-0567
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 69%
from disclosure to weapon0 days
Published on NVDDec 31
1st PoCDec 31
exploitation probability
69%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/733⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-045http://secunia.com/advisories/13466http://securitytracker.com/id?1012517https://exchange.xforce.ibmcloud.com/vulnerabilities/18259http://www.ciac.org/ciac/bulletins/p-054.shtmlhttp://www.kb.cert.org/vuls/id/378160http://www.osvdb.org/12370http://www.securityfocus.com/bid/11922