Vulnerability record · CVE-2004-0541 · published 6 August 2004
CVE-2004-0541: Squid Web Proxy NTLM auth buffer overflow allows remote code execution
National Science Foundation · Squid Web Proxy Cache
Squid Web Proxy Cache 2.5.x and 3.x, when built with NTLM handlers enabled, contains a buffer overflow in the ntlm_check_auth function. A long password value overflows the buffer, and because the flaw is reachable over the network without authentication, it can lead to arbitrary code execution on the proxy.
Description
Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with a network-reachable, unauthenticated buffer overflow that yields code execution, plus a very high EPSS percentile.
What it is
Squid Web Proxy Cache 2.5.x and 3.x, when built with NTLM handlers enabled, contains a buffer overflow in the ntlm_check_auth function. A long password value overflows the buffer, and because the flaw is reachable over the network without authentication, it can lead to arbitrary code execution on the proxy.
Impact
A remote attacker can execute arbitrary code with the privileges of the Squid process, giving full control of the proxy host. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.
Attack surface
Reachable over the network via the NTLM authentication handling path (AV:N, AC:L, Au:N), so no authentication or user interaction is required. It only applies to Squid builds compiled with NTLM handlers enabled.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is 0.7107 (99.374th percentile), indicating a high modeled likelihood of exploitation. Several references carry Patch and Vendor Advisory tags, confirming fixes were published.
What to do
- Upgrade to a patched Squid release from your distribution or vendor (Red Hat, Gentoo, Mandrake, Trustix, SGI advisories referenced).
- If NTLM authentication is not required, rebuild Squid without NTLM handlers enabled to remove the vulnerable code path.
- Restrict network access to the Squid proxy so only trusted clients can reach it.
- Monitor vendor advisories for the affected 2.5.x and 3.x branches and apply follow-up updates.
Detection
- Inspect Squid logs for NTLM authentication attempts with abnormally long password fields.
- Alert on crashes or restarts of the squid process that coincide with NTLM auth traffic.
- Use the referenced OVAL definitions to scan hosts for the vulnerable Squid build.
- Watch for unexpected outbound connections or child processes spawned by squid.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0541 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0541), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.