VDB

CVE-2004-0567

CVE-2004-0567 PUBLISHED CVSS 7.5 HIGH

The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."

EPSS 25.25% · 96.3th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
25.25%
96.3th percentile

Affected Products

VendorProductVersions
microsoftwindows_2003_server64-bit, r2
microsoftwindows_2000
microsoftwindows_nt4.0, 4.0
n/an/an/a

Timeline

  • Dec 31, 2004 CVE Published
  • Feb 4, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score
  • Dec 8, 2023 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›