Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2004-0208

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft Windows NT 4.0版本,Windows 2000版本,Windows XP版本和Windows Server 2003版本的Virtual DOS Machine (VDM)子系统存在漏洞。本地用户可以借助恶意程序进入核心内存以及提升特权,该恶意程序以一种通过授予操作系统函数特权来不恰当验证的方式修改一些系统结构。

AI Predicted 7.8 Difficulty: Moderate EPSS 1.53% · P72
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2004-0208

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Windows Kernel Virtual DOS Machine特权提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows NT 4.0版本,Windows 2000版本,Windows XP版本和Windows Server 2003版本的Virtual DOS Machine (VDM)子系统存在漏洞。本地用户可以借助恶意程序进入核心内存以及提升特权,该恶意程序以一种通过授予操作系统函数特权来不恰当验证的方式修改一些系统结构。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2004-0208

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2004-0208

登录查看更多情报信息。

Vendor Advisories for CVE-2004-0208 (9)

Same Patch Batch · n/a · 2004-10-16 · 27 CVEs total

CVE-2004-0815 Samba远程畸形路径名导致目录遍历漏洞
CVE-2004-0959 PHP处理RFC1867 MIME格式导致数组错误漏洞
CVE-2004-0958 PHP PHP_Variables远程内存泄露漏洞
CVE-2004-0938 FreeRADIUS 'Ascend-Send-Secret'远程拒绝服务漏洞
CVE-2004-0885 Apache 安全漏洞
CVE-2004-0846 Microsoft Excel远程任意指令执行漏洞(MS04-033)
CVE-2004-0845 Microsoft Internet Explorer 安全漏洞
CVE-2004-0844 Microsoft Windows Internet Explorer地址栏伪造漏洞(MS04-038)
CVE-2004-0843 Microsoft Internet Explorer 安全漏洞
CVE-2004-0840 多款Microsoft产品SMTP组件和Exchange Routing Engine组件输入验证错误漏洞
CVE-2004-0837 Oracle MySQL 安全漏洞
CVE-2004-0836 Oracle MySQL 缓冲区错误漏洞
CVE-2004-0835 Oracle MySQL 安全漏洞
CVE-2003-0718 Microsoft Internet Information Services 安全漏洞
CVE-2004-0804 libtiff 安全漏洞
CVE-2004-0774 RealNetworks Helix Universal Server部分POST请求远程拒绝服务漏洞
CVE-2004-0575 Microsoft压缩文件夹远程任意命令执行漏洞(MS04-034)
CVE-2004-0574 Microsoft NNTP XPAT命令远程缓冲区错误漏洞(MS04-036)
CVE-2004-0572 Microsoft Windows程序组转换器文件名本地缓冲区溢出漏洞
CVE-2004-0569 Microsoft Windows NT Server RPC实时库信息泄露漏洞(MS04-029)

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2004-0208

No comments yet


Leave a comment