CVE-2004-0119

Description

The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.

Related CPE's

Could not find any relations

References

Third Party AdvisoryUS Government Resource
PatchThird Party AdvisoryUS Government Resource
Broken Link
Broken Link
Third Party AdvisoryVDB Entry
Third Party AdvisoryVDB Entry
Third Party Advisory
Third Party Advisory
Third Party Advisory
PatchVendor Advisory

CvssV3 impact

Could not find any metrics

CvssV2 impact

Version

2.0

VectorString

AV:N/AC:L/Au:N/C:P/I:P/A:P

AccessVector

NETWORK

AccessComplexity

LOW

Authentication

NONE

ConfidentialityImpact

PARTIAL

IntegrityImpact

PARTIAL

AvailabilityImpact

PARTIAL

BaseScore

7.5