CVE-2004-0893

CWE-494 documents4 sources
Severity
7.2HIGH
EPSS
1.3%
top 20.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateApr 29

Description

The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-rm55-79mv-22rp: The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 42022-04-29
CVEList
CVE-2004-0893: The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 42004-12-15

📐Framework References

1
CWE
Path Equivalence: 'filename/' (Trailing Slash)
CVE-2004-0893 (HIGH CVSS 7.2) | The Local Procedure Call (LPC) inte | cvebase.io