CVE-2004-1080
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 80%
from disclosure to weapon132 days
Published on NVDDec 1
1st PoC+132d
metasploit+13d
exploitation probability
80%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/909unverifiedexploitdbwww.exploit-db.com/exploits/16359unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=110150370506704&w=2https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-045http://secunia.com/advisories/13328/http://securitytracker.com/id?1012516https://exchange.xforce.ibmcloud.com/vulnerabilities/18259https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1549https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2541https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2734https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3677https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4372https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4831http://support.microsoft.com/kb/890710