Vulnerability record · CVE-2004-0210 · published 6 August 2004
CVE-2004-0210: Microsoft Windows POSIX component buffer overflow allows local code execution
Microsoft · Interix
The POSIX subsystem in Windows NT and Windows 2000 contains a classic buffer overflow (CWE-120) that can be triggered by local users through crafted parameters, possibly by manipulating message length values. Successful exploitation lets a local user run arbitrary code with elevated privileges, making it a privilege escalation issue on affected hosts.
Description
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows local privilege escalation with high confidentiality, integrity, and availability impact, and it is listed in CISA KEV as exploited in the wild.
What it is
The POSIX subsystem in Windows NT and Windows 2000 contains a classic buffer overflow (CWE-120) that can be triggered by local users through crafted parameters, possibly by manipulating message length values. Successful exploitation lets a local user run arbitrary code with elevated privileges, making it a privilege escalation issue on affected hosts.
Impact
An attacker with local access gains the ability to execute arbitrary code, potentially at higher privilege than their own account. This can lead to full compromise of the affected system.
Attack surface
The vulnerability is reached locally (CVSS vector AV:L) with low privileges required (PR:L) and no user interaction (UI:N). No remote or network vector is described.
Exploitation
CVE-2004-0210 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating exploitation in the wild; EPSS 30-day probability is 0.07214 (93.995th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor patch referenced in Microsoft Security Bulletin MS04-020 (and associated updates) to Windows NT and Windows 2000 systems.
- Retire or isolate unsupported Windows NT and Windows 2000 hosts, as they no longer receive security updates.
- Restrict local interactive logon and privilege assignment to only trusted users on any remaining affected systems.
- Monitor for and block unauthorized local code execution attempts through endpoint controls where feasible.
Detection
- Audit local process creation for unexpected child processes spawned from POSIX subsystem components.
- Monitor for anomalous local privilege escalation events and unusual access to POSIX-related system calls or message-passing interfaces.
- Use host-based detection to flag buffer overflow exploitation patterns in POSIX subsystem processes.
- Track CISA KEV status and verify patching of any remaining Windows NT/2000 assets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2004-0210 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Windows Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0210 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0210), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.