← Vulnerability feed

Vulnerability record · CVE-2004-0572 · published 3 November 2004

CVE-2004-0572: Windows Program Group Converter buffer overflow via shell URL

Microsoft · Grpconv

The Windows Program Group Converter (grpconv.exe) contains a buffer overflow that is triggered when the shell capability launches grpconv.exe to handle a shell: URL containing a long filename with a .grp extension. Because the overflow is reachable over the network with no authentication and yields complete confidentiality, integrity and availability impact, it is a serious remote code execution flaw on affected Windows systems.

10.0 CVSS 2.0 High EPSS 50% · top 1.1%
10.0CVSS 2.0 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and complete impact, plus public exploit code and high EPSS, make this a top-priority legacy flaw.

What it is

The Windows Program Group Converter (grpconv.exe) contains a buffer overflow that is triggered when the shell capability launches grpconv.exe to handle a shell: URL containing a long filename with a .grp extension. Because the overflow is reachable over the network with no authentication and yields complete confidentiality, integrity and availability impact, it is a serious remote code execution flaw on affected Windows systems.

Impact

An attacker can execute arbitrary code with the privileges of the process handling the shell: URL, giving full control of the affected host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

Reached remotely over the network via a crafted shell: URL with a long .grp filename; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication is required. The description implies the victim must trigger the shell capability that launches grpconv.exe, so some form of user interaction is likely but is not explicitly stated in the record.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high (0.49951, 98.8th percentile) and a public exploit reference is tagged in the references, indicating exploit code is publicly available.

What to do

  • Apply the Microsoft security update MS04-037 (or the corresponding vendor patch) to affected Windows systems.
  • Block or restrict handling of shell: URLs and .grp files at email gateways, browsers and proxy layers.
  • Remove or disable the Windows Program Group Converter where it is not required.
  • Limit user privileges so that successful exploitation does not yield administrative rights.
  • Monitor vendor and CERT/CC advisories for updated guidance on this legacy component.

Detection

  • Monitor process creation for grpconv.exe, especially when spawned from browser, mail client or shell URL handling contexts.
  • Alert on shell: URLs containing unusually long filenames or .grp extensions in email, web and proxy logs.
  • Watch for crash or exception events in grpconv.exe that may indicate overflow attempts.
  • Correlate grpconv.exe execution with subsequent suspicious child processes or network connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0290.html ExploitVendor Advisory
http://www.kb.cert.org/vuls/id/543864 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/10677 PatchVendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-037
https://exchange.xforce.ibmcloud.com/vulnerabilities/16664
https://exchange.xforce.ibmcloud.com/vulnerabilities/17662
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1279
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1837
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1843
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2753
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3071
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3768
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3822
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4244
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4493
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0290.html ExploitVendor Advisory
http://www.kb.cert.org/vuls/id/543864 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/10677 PatchVendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-037
https://exchange.xforce.ibmcloud.com/vulnerabilities/16664
https://exchange.xforce.ibmcloud.com/vulnerabilities/17662
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1279
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1837
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1843
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2753
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3071
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3768
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3822
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4244
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4493

Track CVE-2004-0572 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2004-0572), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.