Vulnerability record · CVE-2004-0214 · published 3 November 2004
CVE-2004-0214: Microsoft Internet Explorer and Explorer share name buffer overflow
Microsoft · Internet Explorer
A buffer overflow exists in Microsoft Internet Explorer and Windows Explorer on Windows XP SP1, 2000, 98, and Me when handling long share names, as demonstrated using Samba. A remote malicious server can trigger the overflow, causing a denial of service and possibly arbitrary code execution. The flaw is remotely reachable without authentication and affects widely deployed legacy Windows platforms.
Description
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with remote, unauthenticated, low-complexity exploitation and high EPSS percentile warrants critical priority despite lack of KEV listing.
What it is
A buffer overflow exists in Microsoft Internet Explorer and Windows Explorer on Windows XP SP1, 2000, 98, and Me when handling long share names, as demonstrated using Samba. A remote malicious server can trigger the overflow, causing a denial of service and possibly arbitrary code execution. The flaw is remotely reachable without authentication and affects widely deployed legacy Windows platforms.
Impact
An attacker can crash the affected application and potentially execute arbitrary code with the privileges of the user. Successful exploitation could lead to full system compromise.
Attack surface
The vulnerability is reached over the network via a malicious server returning long share names, requiring no authentication or user interaction beyond connecting to the server. The CVSS vector AV:N/AC:L/Au:N confirms remote, low-complexity, unauthenticated access.
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS is high at 0.46978 (98.8th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the Microsoft security update MS04-037 for affected Windows versions.
- Upgrade or migrate from unsupported Windows XP SP1, 2000, 98, and Me systems.
- Restrict outbound SMB and file-sharing traffic to trusted servers only.
- Disable or limit access to untrusted network shares and servers.
- Monitor for and block connections to known malicious or untrusted SMB servers.
Detection
- Monitor for crashes of explorer.exe or iexplore.exe when accessing network shares.
- Inspect network traffic for unusually long share names in SMB or related protocols.
- Review endpoint logs for abnormal process terminations or code execution following share access.
- Use IDS/IPS signatures targeting long share name patterns in SMB traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0214 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0214), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.