CVE-2004-0892
Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 17.36% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/isa server · microsoft/proxy server · microsoft/windows 2003 server
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/11605Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-039
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17906
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4264
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4859
- http://www.securityfocus.com/bid/11605Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-039
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17906
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4264
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4859
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.