← back
CVE-2004-0210

CVE-2004-0210

CVSS 7.8 HIGHEPSS 7.6%● KEVCWE-120
Vexday Risk Score
71High priority
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 7.6%KEV simPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
14 Jul 2004Published on NVD
16 Jul 2004Public PoC
03 Mar 2022Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A vulnerability in Windows NT and Windows 2000's POSIX component allows local users to run arbitrary code by exploiting a buffer overflow through specially crafted parameters that modify message length values.

Technical detail

A buffer overflow vulnerability exists in the POSIX subsystem of Windows NT/2000, exploitable by local attackers via manipulation of message length parameters. The vulnerability requires local access and results in arbitrary code execution with the privileges of the affected process.

Summary generated and translated by AI from the official description.
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →