SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0567

The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote…

HIGH 7.5EPSS 68.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 68.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
68.69% probability · 99th percentile
CISA KEV
Not listed
Affected
microsoft/windows 2000 · microsoft/windows 2003 server · microsoft/windows nt
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.