Executive brief
A buffer overflow vulnerability in the POSIX subsystem of Microsoft Windows NT and 2000 allows local users to execute arbitrary code with elevated privileges. The flaw is triggered by modifying message length values in certain parameters, potentially leading to a complete system takeover.
Affected products
- Microsoft Windows 2000 SP2, SP3, SP4
- Microsoft Windows NT 4.0 SP6a
- Microsoft Interix 2.2
Timeline
- 2004-07-13: advisory: Microsoft MS04-020 security bulletin published.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.