CVE-2004-0567
Last modified
CVE-2004-0567 is a vulnerability of currently unknown severity. The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability.". EPSS estimates a 72.29% chance of exploitation in the next 30 days.
Description
The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows 2000 | All versions | Sp3 |
| Microsoft | Windows 2003 Server | 64-bit | — |
| Microsoft | Windows 2003 Server | r2 | — |
| Microsoft | Windows Nt | 4.0 | Sp6 |
References
- http://www.ciac.org/ciac/bulletins/p-054.shtmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/378160Patch, Third Party Advisory, US Government Resource
- http://www.ciac.org/ciac/bulletins/p-054.shtmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/378160Patch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0567?
How severe is CVE-2004-0567?
How do I fix CVE-2004-0567?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0561Format string vulnerability in the log routine for gopher da…
- CVE-2004-0562Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2004-0563The tspc.conf configuration file in freenet6 before 0.9.6 an…
- CVE-2004-0564Roaring Penguin pppoe (rp-ppoe), if installed or configured …
- CVE-2004-0565Floating point information leak in the context switch code f…
- CVE-2004-0566Integer overflow in imgbmp.cxx for Windows 2000 allows remot…
- CVE-2004-0568HyperTerminal application for Windows NT 4.0, Windows 2000, …
- CVE-2004-0569The RPC Runtime Library for Microsoft Windows NT 4.0 allows …
- CVE-2004-0571Microsoft Word for Windows 6.0 Converter does not properly v…
- CVE-2004-0572Buffer overflow in the Windows Program Group Converter (grpc…
- CVE-2004-0573Buffer overflow in the converter for Microsoft WordPerfect 5…
- CVE-2004-0574The Network News Transfer Protocol (NNTP) component of Micro…
Are you affected by CVE-2004-0567?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
