VDB
CVE-2004-0567
CVE-2004-0567
PUBLISHED
CVSS 7.5 HIGH
The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."
EPSS 25.25% · 96.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
25.25%
96.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_2003_server | 64-bit, r2 |
| microsoft | windows_2000 | |
| microsoft | windows_nt | 4.0, 4.0 |
| n/a | n/a | n/a |
Timeline
- Dec 31, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 8, 2023 EPSS Score
References
- 13466 third-party-advisory
- VU#378160 third-party-advisory
- 1012517 vdb
- 12370 vdb
- wins-memory-pointer-hijack(18259) vdb
- 11922 vdb
- P-054 third-party-advisory
- MS04-045 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0567 advisory