CVE-2004-0899
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 72.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 72.57% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows nt
- Source
- cve@mitre.org
References
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-042
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18341
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2280
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4282
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-042
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18341
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2280
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4282
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.