Vulnerability record · CVE-2004-0567 · published 31 December 2004
CVE-2004-0567: Microsoft WINS name validation buffer overflow allows remote code execution
Microsoft · Windows 2000
WINS on Windows NT Server 4.0 SP6a, NT Terminal Server 4.0 SP6, Windows 2000 Server SP3/SP4, and Windows Server 2003 fails to properly validate the computer name value in a WINS packet. The unchecked buffer can be overflowed, letting a remote attacker execute arbitrary code or crash the service. Because WINS is a core name-resolution service, a compromise can affect dependent systems.
Description
The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityCVSS 2.0 base score 7.5 with a network, unauthenticated vector and high EPSS probability, though the affected platforms are legacy and no KEV listing or known exploit is documented.
What it is
WINS on Windows NT Server 4.0 SP6a, NT Terminal Server 4.0 SP6, Windows 2000 Server SP3/SP4, and Windows Server 2003 fails to properly validate the computer name value in a WINS packet. The unchecked buffer can be overflowed, letting a remote attacker execute arbitrary code or crash the service. Because WINS is a core name-resolution service, a compromise can affect dependent systems.
Impact
A remote attacker can execute arbitrary code in the WINS service context or cause a denial of service by crashing the server. Successful code execution could give the attacker control of the WINS host and a foothold on the network.
Attack surface
Reachable over the network via a crafted WINS packet to the WINS service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is 0.68689 (99.3rd percentile), indicating a high modeled likelihood of exploitation; references include patch and vendor advisory tags only, with no public exploit tag.
What to do
- Apply the Microsoft security update for MS04-045 (or later cumulative updates) to all affected WINS servers.
- If WINS is not required, disable or remove the WINS service on affected hosts.
- Restrict network access to WINS (TCP/UDP 42) to trusted internal hosts only.
- Retire or isolate unsupported Windows NT 4.0 and Windows 2000 Server systems that cannot be patched.
- Monitor vendor advisories for any updated guidance on this legacy service.
Detection
- Monitor WINS service logs and Windows event logs for unexpected crashes or restarts of the WINS service.
- Inspect network traffic to WINS ports for malformed or unusually long computer name fields in WINS packets.
- Alert on unexpected processes or child processes spawned by the WINS service process.
- Track repeated WINS service failures across hosts, which may indicate exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0567 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0567), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.