← Vulnerability feed

Vulnerability record · CVE-2004-0214 · published 3 November 2004

CVE-2004-0214: Microsoft Internet Explorer and Explorer share name buffer overflow

Microsoft · Internet Explorer

A buffer overflow exists in Microsoft Internet Explorer and Windows Explorer on Windows XP SP1, 2000, 98, and Me when handling long share names, as demonstrated using Samba. A remote malicious server can trigger the overflow, causing a denial of service and possibly arbitrary code execution. The flaw is remotely reachable without authentication and affects widely deployed legacy Windows platforms.

10.0 CVSS 2.0 High EPSS 47% · top 1.2%
10.0CVSS 2.0 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with remote, unauthenticated, low-complexity exploitation and high EPSS percentile warrants critical priority despite lack of KEV listing.

What it is

A buffer overflow exists in Microsoft Internet Explorer and Windows Explorer on Windows XP SP1, 2000, 98, and Me when handling long share names, as demonstrated using Samba. A remote malicious server can trigger the overflow, causing a denial of service and possibly arbitrary code execution. The flaw is remotely reachable without authentication and affects widely deployed legacy Windows platforms.

Impact

An attacker can crash the affected application and potentially execute arbitrary code with the privileges of the user. Successful exploitation could lead to full system compromise.

Attack surface

The vulnerability is reached over the network via a malicious server returning long share names, requiring no authentication or user interaction beyond connecting to the server. The CVSS vector AV:N/AC:L/Au:N confirms remote, low-complexity, unauthenticated access.

Exploitation

The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS is high at 0.46978 (98.8th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the Microsoft security update MS04-037 for affected Windows versions.
  • Upgrade or migrate from unsupported Windows XP SP1, 2000, 98, and Me systems.
  • Restrict outbound SMB and file-sharing traffic to trusted servers only.
  • Disable or limit access to untrusted network shares and servers.
  • Monitor for and block connections to known malicious or untrusted SMB servers.

Detection

  • Monitor for crashes of explorer.exe or iexplore.exe when accessing network shares.
  • Inspect network traffic for unusually long share names in SMB or related protocols.
  • Review endpoint logs for abnormal process terminations or code execution following share access.
  • Use IDS/IPS signatures targeting long share name patterns in SMB traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/lists/bugtraq/2004/Apr/0322.html Vendor Advisory
http://seclists.org/lists/fulldisclosure/2004/Apr/0933.html Vendor Advisory
http://secunia.com/advisories/11482/
http://securitytracker.com/id?1011647
http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B322857
http://www.kb.cert.org/vuls/id/616200 US Government Resource
http://www.osvdb.org/5687
http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html
http://www.securityfocus.com/bid/10213
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-037
https://exchange.xforce.ibmcloud.com/vulnerabilities/15956
https://exchange.xforce.ibmcloud.com/vulnerabilities/17662
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1601
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1749
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2638
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4345
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5307
http://seclists.org/lists/bugtraq/2004/Apr/0322.html Vendor Advisory
http://seclists.org/lists/fulldisclosure/2004/Apr/0933.html Vendor Advisory
http://secunia.com/advisories/11482/
http://securitytracker.com/id?1011647
http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B322857
http://www.kb.cert.org/vuls/id/616200 US Government Resource
http://www.osvdb.org/5687
http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html
http://www.securityfocus.com/bid/10213
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-037
https://exchange.xforce.ibmcloud.com/vulnerabilities/15956
https://exchange.xforce.ibmcloud.com/vulnerabilities/17662
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1601
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1749
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2638
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4345
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5307

Track CVE-2004-0214 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-0313Adobe Flash Player use-after-free allows remote code executionAdobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x…KEVEPSS 95%analysed9.8CVE-2015-0311Adobe Flash Player unspecified flaw allows remote code executionCVE-2015-0311 is an unspecified vulnerability in Adobe Flash Player affecting versions through 13.0.0.262, 14.x, 15.x, and 16.x through 16.0.0.287 on…KEVEPSS 86%analysed9.8CVE-2014-1776Internet Explorer use-after-free in CMarkup::IsConnectedToPrimaryMarkupMicrosoft Internet Explorer 6 through 11 contains a use-after-free in the CMarkup::IsConnectedToPrimaryMarkup function that allows remote code execut…KEVEPSS 83%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2021-27085Microsoft Internet Explorer remote code execution flawCVE-2021-27085 is a remote code execution vulnerability in Microsoft Internet Explorer. The record gives only a one-line description and no root-caus…KEVEPSS 5.4%analysed8.8CVE-2021-26411Microsoft Internet Explorer and Edge use-after-free memory corruptionCVE-2021-26411 is a use-after-free (CWE-416) memory corruption flaw in Microsoft Internet Explorer, with Microsoft Edge also listed as an affected pr…KEVEPSS 81%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2017-0222Internet Explorer memory corruption out-of-bounds write RCEInternet Explorer improperly accesses objects in memory, causing an out-of-bounds write (CWE-787) that can be turned into remote code execution. The …KEVEPSS 30%analysed

Source: NIST National Vulnerability Database (record CVE-2004-0214), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.