Back
CVE-2004-0123
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Published: Jun 1, 2004
Modified: Jun 16, 2026
CWE-119
CVSS Metrics
Affected Products (7)
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_2000 | * |
| microsoft | windows_2003_server | r2 |
| microsoft | windows_98 | * |
| microsoft | windows_98se | * |
| microsoft | windows_me | * |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_xp | * |
GitHub Security Advisory GHSA-mp49-4xhv-78fw
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows...
References (18)
- http://www.ciac.org/ciac/bulletins/o-114.shtml
- http://www.kb.cert.org/vuls/id/255924 Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/10118
- http://www.us-cert.gov/cas/techalerts/TA04-104A.html Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15713
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1007
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1076
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A924
- http://www.ciac.org/ciac/bulletins/o-114.shtml
- http://www.kb.cert.org/vuls/id/255924 Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/10118
- http://www.us-cert.gov/cas/techalerts/TA04-104A.html Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15713
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
29.75%
Top 2% most likely to be exploited
Threat Score
38.9 / 100
Data Sources
NVD
EPSS
GitHub