CVE-2004-0899

Windows NT 4.0 - Denial of Service via Malformed DHCP Message

Title source: llm
STIX 2.1

Description

The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18341
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4282
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2280

Scores

EPSS 0.7257
EPSS Percentile 99.4%

Details

Status published
Products (1)
microsoft/windows_nt 4.0 (40 CPE variants)
Published Jan 10, 2005
Tracked Since Feb 18, 2026