First published: Wed Jul 14 2004(Updated: )
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya DEFINITY ONE Media Server | ||
Microsoft Internet Explorer | =6.0-sp1 | |
Avaya S8100 | ||
Avaya IP600 Media Servers | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows NT | =4.0-sp6a | |
Microsoft Windows XP | =gold | |
Microsoft Windows 2000 | ||
Microsoft Windows XP | ||
Microsoft Windows 2000 | =sp4 | |
Avaya Modular Messaging Message Storage Server | =s3400 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows NT | =4.0-sp6a | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows NT | =4.0-sp6a | |
Microsoft Windows 2000 | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0212 is classified as a critical vulnerability due to its potential for arbitrary code execution.
To fix CVE-2004-0212, install the latest patches and updates provided by Microsoft for affected Windows versions.
CVE-2004-0212 affects Windows 2000, Windows XP, and Internet Explorer 6 on Windows NT 4.0.
Yes, CVE-2004-0212 can be exploited remotely through crafted .job files.
CVE-2004-0212 can facilitate stack-based buffer overflow attacks leading to arbitrary code execution.