Back
CVE-2004-0567
The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (6)
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_2000 | * |
| microsoft | windows_2000 | * |
| microsoft | windows_2003_server | 64-bit |
| microsoft | windows_2003_server | r2 |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_nt | 4.0 |
GitHub Security Advisory GHSA-qfjv-m3mh-pmwp
The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0...
References (16)
- http://secunia.com/advisories/13466
- http://securitytracker.com/id?1012517
- http://www.ciac.org/ciac/bulletins/p-054.shtml Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/378160 Patch, Third Party Advisory, US Government Resource
- http://www.osvdb.org/12370
- http://www.securityfocus.com/bid/11922
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-045
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18259
- http://secunia.com/advisories/13466
- http://securitytracker.com/id?1012517
- http://www.ciac.org/ciac/bulletins/p-054.shtml Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/378160 Patch, Third Party Advisory, US Government Resource
- http://www.osvdb.org/12370
- http://www.securityfocus.com/bid/11922
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-045
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
68.69%
Top 1% most likely to be exploited
Threat Score
50.6 / 100
Data Sources
NVD
EPSS
GitHub