CVE-2004-0900
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 26.04% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows nt
- Source
- cve@mitre.org
References
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-042
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18342
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3577
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4846
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-042
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18342
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3577
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4846
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.