CVE-2004-0900

Windows NT 4.0 - Remote Code Execution via Malformed DHCP Message

Title source: llm
STIX 2.1

Description

The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3577
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4846
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18342

Scores

EPSS 0.2604
EPSS Percentile 97.8%

Details

Status published
Products (1)
microsoft/windows_nt 4.0 (40 CPE variants)
Published Jan 10, 2005
Tracked Since Feb 18, 2026