VulnerabilityAnalyzed
CVE-2004-0210
Microsoft Windows Privilege Escalation Vulnerability
KEVHIGH 7.8EPSS 7.21%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 7.21% probability · 94th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022
- Weakness
- CWE-120
- Affected
- microsoft/interix · microsoft/windows 2000 · microsoft/windows nt
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2004-0210
References
- http://www.kb.cert.org/vuls/id/647436Patch, Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-196A.htmlBroken Link, Patch, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-020Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16590Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2166Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2847Broken Link
- http://www.kb.cert.org/vuls/id/647436Patch, Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-196A.htmlBroken Link, Patch, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-020Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16590Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2166Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2847Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-0210US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.