Vulnerability Name: | CVE-2004-0119 (CCN-15715) | ||||||||||||||||
Assigned: | 2004-04-13 | ||||||||||||||||
Published: | 2004-04-13 | ||||||||||||||||
Updated: | 2020-11-13 | ||||||||||||||||
Summary: | The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-476 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: VULNWATCH Type: Broken Link 20040414 NSFOCUS SA2004-01 : DoS Vulnerability in Microsoft Windows SPNEGO Protocol Decoding Source: MITRE Type: CNA CVE-2004-0119 Source: CCN Type: CIAC Information Bulletin O-114 Microsoft Security Update for Microsoft Windows [REVISED 25 Jun 2004] Source: CIAC Type: Broken Link O-114 Source: CCN Type: US-CERT VU#638548 Microsoft Windows SSP interface fails to properly validate value used during authentication protocol selection Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#638548 Source: CCN Type: Microsoft Security Bulletin MS04-011 Security Update for Microsoft Windows (835732) Source: CCN Type: NSFOCUS Security Advisory SA2004-01 NSFOCUS Security Advisory(SA2004-01) DoS Vulnerability in Microsoft Windows SPNEGO Protocol Decoding Source: BID Type: Third Party Advisory, VDB Entry 10113 Source: CCN Type: BID-10113 Microsoft Negotiate SSP Remote Buffer Overflow Vulnerability Source: CERT Type: Third Party Advisory, US Government Resource TA04-104A Source: CCN Type: Internet Security Systems Security Alert, April 13, 2004 Multiple Vulnerabilities in Microsoft Products Source: MS Type: Patch, Vendor Advisory MS04-011 Source: XF Type: Third Party Advisory, VDB Entry win-spp-bo(15715) Source: XF Type: UNKNOWN win-spp-bo(15715) Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:1808 Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:1962 Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:1997 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |