CVE-2004-0116
CVE information
Published
Last Modified
CVSSv2.0 Severity
Impact Analysis
Description
An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field..
CVSSv2.0 Score
- Severity
- Medium
- Base Score
- 5/10
- Exploit Score
- 10/10
- Access Vector
- Network
- Access Complexity
- Low
- Authentication Required
- None
- Impact Score
- 2.9/10
- Confidentiality Impact
- None
- Availability Impact
- Partial
- Integrity Impact
- None
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:microsoft:windows_xp:*:gold:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:* |
Yes
|
- | - |
References
- http://www.eeye.com/html/Research/Advisories/AD20040413A.html
- http://www.us-cert.gov/cas/techalerts/TA04-104A.html
- http://www.kb.cert.org/vuls/id/417052
- http://www.ciac.org/ciac/bulletins/o-115.shtml
- http://www.securityfocus.com/bid/10127
- http://securitytracker.com/alerts/2004/Apr/1009758.html
- http://secunia.com/advisories/11065/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15708
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012