Vulnerability Name: | CVE-2004-0212 (CCN-16591) | ||||||||||||||||||||
Assigned: | 2004-07-13 | ||||||||||||||||||||
Published: | 2004-07-13 | ||||||||||||||||||||
Updated: | 2019-04-30 | ||||||||||||||||||||
Summary: | Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share. | ||||||||||||||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2004-0212 Source: BUGTRAQ Type: UNKNOWN 20040714 Microsoft Windows Task Scheduler '.job' Stack Overflow Source: BUGTRAQ Type: UNKNOWN 20040714 Unchecked buffer in mstask.dll Source: CCN Type: SA12060 Microsoft Windows Task Scheduler Buffer Overflow Vulnerability Source: SECUNIA Type: UNKNOWN 12060 Source: CCN Type: CIAC Information Bulletin 0-178 Vulnerability in Task Scheduler Could Allow Code Execution Source: CCN Type: US-CERT VU#228028 Microsoft Windows Task Scheduler Buffer Overflow Source: CERT-VN Type: US Government Resource VU#228028 Source: CCN Type: Microsoft Security Bulletin MS04-022 Vulnerability in Task Scheduler Could Allow Code Execution (841873) Source: CCN Type: NGSSoftware Insight Security Research Advisory #NISR13072004 Microsoft Windows Task Scheduler '.job' Stack Overflow Source: MISC Type: UNKNOWN http://www.ngssoftware.com/advisories/mstaskjob.txt Source: CCN Type: OSVDB ID: 7798 Microsoft Windows Task Scheduler Remote Overflow Source: CCN Type: BID-10708 Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability Source: CERT Type: Patch, Third Party Advisory, US Government Resource TA04-196A Source: MS Type: UNKNOWN MS04-022 Source: XF Type: UNKNOWN win-taskscheduler-bo(16591) Source: XF Type: UNKNOWN win-taskscheduler-bo(16591) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1344 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1781 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1964 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:3428 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |