← Vulnerability feed

Vulnerability record · CVE-2004-0362 · published 15 April 2004

CVE-2004-0362: ISS PAM ICQ Parsing Stack Buffer Overflows Allow Remote Code Execution

Iss · Blackice Agent Server

The ISS Protocol Analysis Module (PAM) used in RealSecure, Proventia and BlackICE products contains multiple stack-based buffer overflows in its ICQ parsing routines. A remote attacker can trigger them with a crafted SRV_MULTI response carrying a SRV_USER_ONLINE packet and a SRV_META_USER packet with oversized nickname, firstname, lastname or email fields. Because PAM inspects network traffic, the flaw sits in the inspection path itself and can be reached without authentication.

7.5 CVSS 2.0 High EPSS 73% · top 0.6%
7.5CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityRemote, unauthenticated code execution in network inspection products, with confirmed worm exploitation and very high EPSS, makes this an urgent patch-or-isolate case.

What it is

The ISS Protocol Analysis Module (PAM) used in RealSecure, Proventia and BlackICE products contains multiple stack-based buffer overflows in its ICQ parsing routines. A remote attacker can trigger them with a crafted SRV_MULTI response carrying a SRV_USER_ONLINE packet and a SRV_META_USER packet with oversized nickname, firstname, lastname or email fields. Because PAM inspects network traffic, the flaw sits in the inspection path itself and can be reached without authentication.

Impact

Successful exploitation allows remote code execution with the privileges of the affected service, giving an attacker full control of the host running the vulnerable ISS product. The Witty worm used this flaw to spread and destroy data on infected systems.

Attack surface

Reachable over the network via ICQ protocol traffic processed by the PAM component; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host running an affected RealSecure, Proventia or BlackICE product that parses ICQ traffic is exposed.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high (0.7333, 99.4th percentile) and references are tagged Exploit, and the description states the Witty worm exploited it. Active exploitation in the wild is therefore established.

What to do

  • Apply the vendor patches referenced in the ISS X-Force alert and CERT/CC advisory VU#947254 for all affected RealSecure, Proventia and BlackICE products.
  • If patching is not immediately possible, disable or block ICQ protocol inspection in PAM until the update is applied.
  • Filter or block inbound ICQ traffic at network boundaries where it is not operationally required.
  • Retire or isolate end-of-life ISS/IBM RealSecure and BlackICE products that no longer receive vendor support.
  • Verify patch level on all PAM-enabled sensors, agents and desktop protections, not just perimeter devices.

Detection

  • Monitor IDS/IPS and PAM logs for malformed or oversized ICQ SRV_MULTI, SRV_USER_ONLINE and SRV_META_USER packets.
  • Alert on crashes, restarts or unexpected process termination of RealSecure, Proventia or BlackICE services.
  • Hunt for Witty-like worm artifacts, including unusual outbound ICQ traffic from monitored hosts and unexpected file or registry modifications.
  • Review network flow data for ICQ traffic to or from hosts that should not be using the protocol.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0362 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2007-2690Iss proventia a series xpu vulnerabilityMultiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode charac…EPSS 2.0%7.5CVE-2004-0193Iss blackice agent server vulnerabilityHeap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Pr…EPSS 8.0%7.2CVE-2005-2711Iss blackice agent server vulnerabilityISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and …EPSS 0.37%7.1CVE-2004-1714Iss blackice pc protection incorrect permission assignment vulnerabilityBlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control…EPSS 0.85%5.0CVE-2006-3840Iss blackice pc protection vulnerabilityThe SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and…EPSS 2.4%4.6CVE-2006-4541Iss blackice pc protection improper input validation vulnerabilityRapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a …EPSS 0.73%4.6CVE-2006-3999Iss blackice pc protection vulnerabilityISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll BlackICE libr…EPSS 0.33%4.6CVE-2004-2125Iss blackice agent server vulnerabilityBuffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users t…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2004-0362), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.