CVE-2004-0574
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 64.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 64.45% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- microsoft/exchange server · microsoft/windows 2000 · microsoft/windows nt · microsoft/windows server 2003
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109761632831563&w=2Mailing List, Third Party Advisory
- http://www.ciac.org/ciac/bulletins/p-012.shtmlBroken Link
- http://www.coresecurity.com/common/showdoc.php?idx=420&idxseccion=10Third Party Advisory
- http://www.kb.cert.org/vuls/id/203126Patch, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-036Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17641Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17661Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A246Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4392Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5021Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5070Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5926Third Party Advisory
- http://marc.info/?l=bugtraq&m=109761632831563&w=2Mailing List, Third Party Advisory
- http://www.ciac.org/ciac/bulletins/p-012.shtmlBroken Link
- http://www.coresecurity.com/common/showdoc.php?idx=420&idxseccion=10Third Party Advisory
- http://www.kb.cert.org/vuls/id/203126Patch, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-036Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17641Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17661Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A246Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4392Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5021Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5070Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5926Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.