CVE-2004-0210
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Windows Privilege Escalation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 7% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-120
מוצרים מושפעים
microsoft: interix; microsoft: windows 2000; microsoft: windows nt
קישורים
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-… PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-… PatchVendor Advisory
- http://www.kb.cert.org/vuls/id/647436 PatchThird Party AdvisoryUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-196A.html Broken LinkPatchThird Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/647436 PatchThird Party AdvisoryUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-196A.html Broken LinkPatchThird Party AdvisoryUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16590 Third Party AdvisoryVDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval… Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval… Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16590 Third Party AdvisoryVDB Entry