Vulnerability record · CVE-2004-0574 · published 3 November 2004
CVE-2004-0574: Microsoft NNTP XPAT pattern buffer overflow allows remote code execution
Microsoft · Exchange Server
The NNTP component in Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server and Exchange Server 2003 mishandles XPAT patterns, with improper length validation and an unchecked buffer leading to off-by-one and heap-based overflows. A remote, unauthenticated attacker can trigger memory corruption over the network, making this a full-impact pre-authentication flaw on internet-exposed NNTP services.
Description
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network vector, no authentication and full confidentiality, integrity and availability impact, plus a very high EPSS percentile.
What it is
The NNTP component in Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server and Exchange Server 2003 mishandles XPAT patterns, with improper length validation and an unchecked buffer leading to off-by-one and heap-based overflows. A remote, unauthenticated attacker can trigger memory corruption over the network, making this a full-impact pre-authentication flaw on internet-exposed NNTP services.
Impact
Successful exploitation allows arbitrary code execution in the context of the NNTP service, giving an attacker complete control of confidentiality, integrity and availability on the affected host.
Attack surface
Reachable over the network through the NNTP service (TCP 119/563) by sending crafted XPAT pattern commands; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.64448, 99.2nd percentile), indicating substantial predicted exploitation activity; references are advisories and patch notices only, with no public exploit tagged.
What to do
- Apply the vendor patch from Microsoft Security Bulletin MS04-036 (and the CERT/CC VU#203126 guidance) to all affected Windows and Exchange systems.
- Disable or stop the NNTP service where news functionality is not required, and block TCP 119/563 at network boundaries.
- Restrict NNTP access to trusted hosts via firewall rules or IP allowlists if the service must remain enabled.
- Retire or isolate end-of-life platforms such as Windows NT 4.0 and Windows 2000 that no longer receive security updates.
Detection
- Monitor NNTP traffic for malformed or unusually long XPAT commands and other anomalous pattern arguments.
- Alert on NNTP service crashes, restarts or unexpected process terminations on servers running the affected component.
- Review network logs for inbound connections to TCP 119/563 from untrusted or external sources.
- Hunt for post-exploitation behavior on NNTP hosts, such as new processes spawned by the news service or unexpected outbound connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0574 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0574), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.