← Vulnerability feed

Vulnerability record · CVE-2004-0574 · published 3 November 2004

CVE-2004-0574: Microsoft NNTP XPAT pattern buffer overflow allows remote code execution

Microsoft · Exchange Server

The NNTP component in Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server and Exchange Server 2003 mishandles XPAT patterns, with improper length validation and an unchecked buffer leading to off-by-one and heap-based overflows. A remote, unauthenticated attacker can trigger memory corruption over the network, making this a full-impact pre-authentication flaw on internet-exposed NNTP services.

10.0 CVSS 2.0 High EPSS 64% · top 0.8% CWE-787 · Out-of-bounds write
10.0CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score of 10 with network vector, no authentication and full confidentiality, integrity and availability impact, plus a very high EPSS percentile.

What it is

The NNTP component in Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server and Exchange Server 2003 mishandles XPAT patterns, with improper length validation and an unchecked buffer leading to off-by-one and heap-based overflows. A remote, unauthenticated attacker can trigger memory corruption over the network, making this a full-impact pre-authentication flaw on internet-exposed NNTP services.

Impact

Successful exploitation allows arbitrary code execution in the context of the NNTP service, giving an attacker complete control of confidentiality, integrity and availability on the affected host.

Attack surface

Reachable over the network through the NNTP service (TCP 119/563) by sending crafted XPAT pattern commands; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.64448, 99.2nd percentile), indicating substantial predicted exploitation activity; references are advisories and patch notices only, with no public exploit tagged.

What to do

  • Apply the vendor patch from Microsoft Security Bulletin MS04-036 (and the CERT/CC VU#203126 guidance) to all affected Windows and Exchange systems.
  • Disable or stop the NNTP service where news functionality is not required, and block TCP 119/563 at network boundaries.
  • Restrict NNTP access to trusted hosts via firewall rules or IP allowlists if the service must remain enabled.
  • Retire or isolate end-of-life platforms such as Windows NT 4.0 and Windows 2000 that no longer receive security updates.

Detection

  • Monitor NNTP traffic for malformed or unusually long XPAT commands and other anomalous pattern arguments.
  • Alert on NNTP service crashes, restarts or unexpected process terminations on servers running the affected component.
  • Review network logs for inbound connections to TCP 119/563 from untrusted or external sources.
  • Hunt for post-exploitation behavior on NNTP hosts, such as new processes spawned by the news service or unexpected outbound connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=bugtraq&m=109761632831563&w=2 Mailing ListThird Party Advisory
http://www.ciac.org/ciac/bulletins/p-012.shtml Broken Link
http://www.coresecurity.com/common/showdoc.php?idx=420&idxseccion=10 Third Party Advisory
http://www.kb.cert.org/vuls/id/203126 PatchThird Party AdvisoryUS Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-036 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/17641 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17661 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A246 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4392 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5021 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5070 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5926 Third Party Advisory
http://marc.info/?l=bugtraq&m=109761632831563&w=2 Mailing ListThird Party Advisory
http://www.ciac.org/ciac/bulletins/p-012.shtml Broken Link
http://www.coresecurity.com/common/showdoc.php?idx=420&idxseccion=10 Third Party Advisory
http://www.kb.cert.org/vuls/id/203126 PatchThird Party AdvisoryUS Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-036 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/17641 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17661 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A246 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4392 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5021 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5070 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5926 Third Party Advisory

Track CVE-2004-0574 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21410Microsoft Exchange Server improper authentication privilege escalationCVE-2024-21410 is an improper authentication (CWE-287) elevation of privilege flaw in Microsoft Exchange Server. It is network-reachable with no priv…KEVEPSS 13%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed9.1CVE-2021-34473Microsoft Exchange Server SSRF Enables Remote Code ExecutionCVE-2021-34473 is a critical server-side request forgery (SSRF) flaw in Microsoft Exchange Server that leads to remote code execution. It is part of …KEVEPSS 100%analysed9.1CVE-2021-26855Microsoft Exchange Server SSRF enabling remote code executionCVE-2021-26855 is a server-side request forgery (CWE-918) in Microsoft Exchange Server that is part of the ProxyLogon exploit chain and can lead to r…KEVEPSS 100%analysed9.0CVE-2021-34523Microsoft Exchange Server privilege escalation flawCVE-2021-34523 is a privilege escalation vulnerability in Microsoft Exchange Server. It is a component of the ProxyShell exploit chain, where it is u…KEVEPSS 100%analysed8.8CVE-2023-21529Microsoft Exchange Server deserialization flaw enables remote code executionCVE-2023-21529 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft Exchange Server that allows remote code execution. It carr…KEVEPSS 59%analysed8.8CVE-2022-41080Microsoft Exchange Server elevation of privilegeCVE-2022-41080 is an elevation of privilege vulnerability in Microsoft Exchange Server. A network-reachable attacker with low privileges can exploit …KEVEPSS 77%analysed8.8CVE-2022-41040Microsoft Exchange Server SSRF elevation of privilegeCVE-2022-41040 is a server-side request forgery (SSRF) flaw in Microsoft Exchange Server that allows an authenticated attacker to escalate privileges…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2004-0574), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.