CVE-2004-0362

ISS Protocol Analysis Module - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2004-0362. PoCs published by Metasploit, Sam, including Metasploit module exploits/windows/firewall/blackice_pam_icq.

AI-analyzed exploit summary This exploit targets a stack buffer overflow in ISS products using iss-pam1.dll (CVE-2004-0362). It sends a maliciously crafted UDP packet to trigger arbitrary code execution as LocalSystem, with support for multiple targets and bruteforce capabilities.

Description

Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16464

This exploit targets a stack buffer overflow in ISS products using iss-pam1.dll (CVE-2004-0362). It sends a maliciously crafted UDP packet to trigger arbitrary code execution as LocalSystem, with support for multiple targets and bruteforce capabilities.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ISS Blackice/RealSecure with iss-pam1.dll
No auth needed
Prerequisites: Network access to UDP port 4000 · Vulnerable ISS product with iss-pam1.dll
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Sam · cremotewindows
https://www.exploit-db.com/exploits/168

This exploit targets a buffer overflow vulnerability in ISS BlackICE/RealSecure's iss_pam1.dll via a malformed ICQ packet. It sends a UDP payload with shellcode to achieve remote code execution, establishing a reverse shell to the attacker's specified host and port.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ISS BlackICE/RealSecure (iss_pam1.dll)
No auth needed
Prerequisites: Network access to target · Target must be running vulnerable ISS BlackICE/RealSecure
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/firewall/blackice_pam_icq.rb

This Metasploit module exploits a stack buffer overflow in ISS products using iss-pam1.dll (Blackice/RealSecure) via a malformed UDP packet. It supports multiple targets and bruteforce techniques to achieve arbitrary code execution as LocalSystem.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ISS Blackice/RealSecure with iss-pam1.dll (versions 3.6.06, 3.6.11, and various Windows OS versions)
No auth needed
Prerequisites: Network access to UDP port 4000 · Vulnerable ISS product with ICQ parsing enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_iss
http://xforce.iss.net/xforce/alerts/id/166
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9913
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11073
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/o-104.shtml
Various Sources third-party-advisory x_refsource_eeye
http://www.eeye.com/html/Research/Advisories/AD20040318.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15442
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/4355
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/947254
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=107965651712378&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15543

Scores

EPSS 0.7333
EPSS Percentile 99.4%

Details

Status published
Products (50)
iss/blackice_agent_server 3.6ebz
iss/blackice_agent_server 3.6eca
iss/blackice_agent_server 3.6ecb
iss/blackice_agent_server 3.6ecc
iss/blackice_agent_server 3.6ecd
iss/blackice_agent_server 3.6ece
iss/blackice_agent_server 3.6ecf
iss/blackice_pc_protection 3.6cbz
iss/blackice_pc_protection 3.6cca
iss/blackice_pc_protection 3.6ccb
... and 40 more
Published Apr 15, 2004
Tracked Since Feb 18, 2026