| Vulnerability Name: | CVE-2004-0212 (CCN-16591) | ||||||||||||||||||||
| Assigned: | 2004-07-13 | ||||||||||||||||||||
| Published: | 2004-07-13 | ||||||||||||||||||||
| Updated: | 2019-04-30 | ||||||||||||||||||||
| Summary: | Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share. | ||||||||||||||||||||
| CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2004-0212 Source: BUGTRAQ Type: UNKNOWN 20040714 Microsoft Windows Task Scheduler '.job' Stack Overflow Source: BUGTRAQ Type: UNKNOWN 20040714 Unchecked buffer in mstask.dll Source: CCN Type: SA12060 Microsoft Windows Task Scheduler Buffer Overflow Vulnerability Source: SECUNIA Type: UNKNOWN 12060 Source: CCN Type: CIAC Information Bulletin 0-178 Vulnerability in Task Scheduler Could Allow Code Execution Source: CCN Type: US-CERT VU#228028 Microsoft Windows Task Scheduler Buffer Overflow Source: CERT-VN Type: US Government Resource VU#228028 Source: CCN Type: Microsoft Security Bulletin MS04-022 Vulnerability in Task Scheduler Could Allow Code Execution (841873) Source: CCN Type: NGSSoftware Insight Security Research Advisory #NISR13072004 Microsoft Windows Task Scheduler '.job' Stack Overflow Source: MISC Type: UNKNOWN http://www.ngssoftware.com/advisories/mstaskjob.txt Source: CCN Type: OSVDB ID: 7798 Microsoft Windows Task Scheduler Remote Overflow Source: CCN Type: BID-10708 Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability Source: CERT Type: Patch, Third Party Advisory, US Government Resource TA04-196A Source: MS Type: UNKNOWN MS04-022 Source: XF Type: UNKNOWN win-taskscheduler-bo(16591) Source: XF Type: UNKNOWN win-taskscheduler-bo(16591) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1344 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1781 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1964 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:3428 | ||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
| BACK | |||||||||||||||||||||