Back

CVE-2004-0893

The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."

Published: Jan 10, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (57)

Vendor Product Version
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2003_server datacenter_64-bit
microsoft windows_2003_server enterprise
microsoft windows_2003_server enterprise
microsoft windows_2003_server enterprise_64-bit
microsoft windows_2003_server enterprise_64-bit
microsoft windows_2003_server r2
microsoft windows_2003_server r2
microsoft windows_2003_server r2
microsoft windows_2003_server standard
microsoft windows_2003_server standard
microsoft windows_2003_server web
microsoft windows_2003_server web
microsoft windows_nt 4.0
microsoft windows_nt 4.0
microsoft windows_nt 4.0

…and 37 more

GitHub Security Advisory GHSA-rm55-79mv-22rp

The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000,...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 1.53%

Top 27% most likely to be exploited

Threat Score 29.3 / 100

Data Sources

NVD EPSS GitHub