SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2004-0210

Microsoft Windows Privilege Escalation Vulnerability

KEVHIGH 7.8EPSS 7.21%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
7.21% probability · 94th percentile
CISA KEV
Listed 3 March 2022 · due 24 March 2022
Weakness
CWE-120
Affected
microsoft/interix · microsoft/windows 2000 · microsoft/windows nt
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2004-0210

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.