HIGH · 10.0

CVE-2004-0212

Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file contain...

Vulnerability Description

Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AvayaIp600 Media ServersAll versions
MicrosoftIe6.0
AvayaDefinity One Media ServerAll versions
AvayaS8100All versions
AvayaModular Messaging Message Storage Servers3400
MicrosoftWindows 2000All versions
MicrosoftWindows Nt4.0
MicrosoftWindows XpAll versions

References

FAQ

What is CVE-2004-0212?

CVE-2004-0212 is a vulnerability with a CVSS score of 10.0 (HIGH). Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file contain...

How severe is CVE-2004-0212?

CVE-2004-0212 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0212?

Check the references section above for vendor advisories and patch information. Affected products include: Avaya Ip600 Media Servers, Microsoft Ie, Avaya Definity One Media Server, Avaya S8100, Avaya Modular Messaging Message Storage Server.