Vulnerability record · CVE-2004-0572 · published 3 November 2004
CVE-2004-0572: Windows Program Group Converter buffer overflow via shell URL
Microsoft · Grpconv
The Windows Program Group Converter (grpconv.exe) contains a buffer overflow that is triggered when the shell capability launches grpconv.exe to handle a shell: URL containing a long filename with a .grp extension. Because the overflow is reachable over the network with no authentication and yields complete confidentiality, integrity and availability impact, it is a serious remote code execution flaw on affected Windows systems.
Description
Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and complete impact, plus public exploit code and high EPSS, make this a top-priority legacy flaw.
What it is
The Windows Program Group Converter (grpconv.exe) contains a buffer overflow that is triggered when the shell capability launches grpconv.exe to handle a shell: URL containing a long filename with a .grp extension. Because the overflow is reachable over the network with no authentication and yields complete confidentiality, integrity and availability impact, it is a serious remote code execution flaw on affected Windows systems.
Impact
An attacker can execute arbitrary code with the privileges of the process handling the shell: URL, giving full control of the affected host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reached remotely over the network via a crafted shell: URL with a long .grp filename; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication is required. The description implies the victim must trigger the shell capability that launches grpconv.exe, so some form of user interaction is likely but is not explicitly stated in the record.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high (0.49951, 98.8th percentile) and a public exploit reference is tagged in the references, indicating exploit code is publicly available.
What to do
- Apply the Microsoft security update MS04-037 (or the corresponding vendor patch) to affected Windows systems.
- Block or restrict handling of shell: URLs and .grp files at email gateways, browsers and proxy layers.
- Remove or disable the Windows Program Group Converter where it is not required.
- Limit user privileges so that successful exploitation does not yield administrative rights.
- Monitor vendor and CERT/CC advisories for updated guidance on this legacy component.
Detection
- Monitor process creation for grpconv.exe, especially when spawned from browser, mail client or shell URL handling contexts.
- Alert on shell: URLs containing unusually long filenames or .grp extensions in email, web and proxy logs.
- Watch for crash or exception events in grpconv.exe that may indicate overflow attempts.
- Correlate grpconv.exe execution with subsequent suspicious child processes or network connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0572 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2004-0572), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.