Vulnerability record · CVE-2004-0206 · published 3 November 2004
CVE-2004-0206: Microsoft Windows NetDDE unchecked buffer allows remote code execution
Microsoft · Windows 2000
Network Dynamic Data Exchange (NetDDE) services in multiple Microsoft Windows versions contain an unchecked buffer that can be triggered by a malicious message or application. Successful exploitation allows remote arbitrary code execution or local privilege escalation. The flaw affects Windows 98, NT 4.0, 2000, XP, and Server 2003.
Description
Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityCVSS 2.0 base score is 7.5 (HIGH) and EPSS is very high, but the vulnerability is old and patches are available.
What it is
Network Dynamic Data Exchange (NetDDE) services in multiple Microsoft Windows versions contain an unchecked buffer that can be triggered by a malicious message or application. Successful exploitation allows remote arbitrary code execution or local privilege escalation. The flaw affects Windows 98, NT 4.0, 2000, XP, and Server 2003.
Impact
An attacker can execute arbitrary code with the privileges of the vulnerable service or gain elevated privileges locally. This can lead to full system compromise.
Attack surface
The vulnerability is reachable over the network (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L). No user interaction is indicated by the vector, though the description mentions a malicious application for local privilege escalation.
Exploitation
The CVE is not listed in CISA KEV and no ransomware groups are documented using it. EPSS probability is 0.74657 (99.476th percentile), indicating a high likelihood of exploitation activity.
What to do
- Apply the patch referenced in Microsoft Security Bulletin MS04-031.
- Disable the NetDDE service if it is not required.
- Block NetDDE-related ports and traffic at network boundaries.
- Restrict network access to affected systems to trusted hosts only.
- Upgrade to a supported Windows version if still running affected legacy systems.
Detection
- Monitor for unexpected NetDDE service crashes or restarts.
- Look for anomalous network traffic to NetDDE ports (e.g., 135, 139, 445) from untrusted sources.
- Audit process creation events for suspicious child processes spawned by NetDDE services.
- Check for unauthorized changes to NetDDE registry keys or service configurations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0206 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0206), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.