CVE-2004-0574
published 2004-11-03CVE-2004-0574: The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and…
PriorityP262critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
67.82%
99.2th percentile
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | windows_nt | — | — |
| microsoft | windows_server_2003 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect oversized XPAT command arguments on NNTP port 119; the PoC uses a pattern of 1946 'C' characters followed by a space and 10 'X' characters, totalling well beyond normal XPAT argument length, indicative of heap overflow attempt. ↗
- →Monitor NNTP (port 119) traffic for XPAT commands with abnormally long pattern arguments (e.g., >1000 bytes), which may indicate exploitation of the unchecked buffer / heap overflow in the NNTP XPAT handler. ↗
- →The exploit targets the newsgroup 'control.newgroup'; monitor for NNTP GROUP commands selecting this or other control.* newsgroups prior to a large XPAT command as a precursor pattern. ↗
- →The vulnerability is triggered via XPAT patterns with improper length validation leading to off-by-one and heap-based buffer overflows; alert on XPAT commands exceeding safe length thresholds on NNTP services. ↗
- ·The PoC hardcodes the target as localhost (127.0.0.1); in real-world exploitation the target host would vary. Detection should not rely on a specific source IP. ↗
- ·This PoC is described as a Denial of Service / proof-of-concept only (MS04-036); actual remote code execution exploits may use different payload sizes or patterns beyond the 1946+10 byte pattern shown. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=109761632831563&w=2http://www.ciac.org/ciac/bulletins/p-012.shtmlhttp://www.coresecurity.com/common/showdoc.php?idx=420&idxseccion=10http://www.kb.cert.org/vuls/id/203126https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-036https://exchange.xforce.ibmcloud.com/vulnerabilities/17641https://exchange.xforce.ibmcloud.com/vulnerabilities/17661https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A246https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4392https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5021https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5070https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5926http://marc.info/?l=bugtraq&m=109761632831563&w=2http://www.ciac.org/ciac/bulletins/p-012.shtmlhttp://www.coresecurity.com/common/showdoc.php?idx=420&idxseccion=10http://www.kb.cert.org/vuls/id/203126https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-036https://exchange.xforce.ibmcloud.com/vulnerabilities/17641https://exchange.xforce.ibmcloud.com/vulnerabilities/17661https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A246https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4392https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5021https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5070https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5926
2004-11-03
Published