Vulnerability record · CVE-2004-0362 · published 15 April 2004
CVE-2004-0362: ISS PAM ICQ Parsing Stack Buffer Overflows Allow Remote Code Execution
Iss · Blackice Agent Server
The ISS Protocol Analysis Module (PAM) used in RealSecure, Proventia and BlackICE products contains multiple stack-based buffer overflows in its ICQ parsing routines. A remote attacker can trigger them with a crafted SRV_MULTI response carrying a SRV_USER_ONLINE packet and a SRV_META_USER packet with oversized nickname, firstname, lastname or email fields. Because PAM inspects network traffic, the flaw sits in the inspection path itself and can be reached without authentication.
Description
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityRemote, unauthenticated code execution in network inspection products, with confirmed worm exploitation and very high EPSS, makes this an urgent patch-or-isolate case.
What it is
The ISS Protocol Analysis Module (PAM) used in RealSecure, Proventia and BlackICE products contains multiple stack-based buffer overflows in its ICQ parsing routines. A remote attacker can trigger them with a crafted SRV_MULTI response carrying a SRV_USER_ONLINE packet and a SRV_META_USER packet with oversized nickname, firstname, lastname or email fields. Because PAM inspects network traffic, the flaw sits in the inspection path itself and can be reached without authentication.
Impact
Successful exploitation allows remote code execution with the privileges of the affected service, giving an attacker full control of the host running the vulnerable ISS product. The Witty worm used this flaw to spread and destroy data on infected systems.
Attack surface
Reachable over the network via ICQ protocol traffic processed by the PAM component; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host running an affected RealSecure, Proventia or BlackICE product that parses ICQ traffic is exposed.
Exploitation
The record is not listed in CISA KEV, but EPSS is very high (0.7333, 99.4th percentile) and references are tagged Exploit, and the description states the Witty worm exploited it. Active exploitation in the wild is therefore established.
What to do
- Apply the vendor patches referenced in the ISS X-Force alert and CERT/CC advisory VU#947254 for all affected RealSecure, Proventia and BlackICE products.
- If patching is not immediately possible, disable or block ICQ protocol inspection in PAM until the update is applied.
- Filter or block inbound ICQ traffic at network boundaries where it is not operationally required.
- Retire or isolate end-of-life ISS/IBM RealSecure and BlackICE products that no longer receive vendor support.
- Verify patch level on all PAM-enabled sensors, agents and desktop protections, not just perimeter devices.
Detection
- Monitor IDS/IPS and PAM logs for malformed or oversized ICQ SRV_MULTI, SRV_USER_ONLINE and SRV_META_USER packets.
- Alert on crashes, restarts or unexpected process termination of RealSecure, Proventia or BlackICE services.
- Hunt for Witty-like worm artifacts, including unusual outbound ICQ traffic from monitored hosts and unexpected file or registry modifications.
- Review network flow data for ICQ traffic to or from hosts that should not be using the protocol.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0362 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0362), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.