Vulnerability record · CVE-2004-0899 · published 10 January 2005
CVE-2004-0899: Windows NT DHCP Server logging length validation denial of service
Microsoft · Windows Nt
The DHCP Server service in Microsoft Windows NT 4.0 Server and Terminal Server Edition fails to validate the length of certain messages when DHCP logging is enabled. A malformed DHCP message can crash the service, taking down DHCP for clients that depend on it. The flaw only applies when logging is turned on.
Description
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is a remotely reachable denial of service but only affects legacy Windows NT 4.0 systems and requires DHCP logging to be enabled, limiting real-world exposure.
What it is
The DHCP Server service in Microsoft Windows NT 4.0 Server and Terminal Server Edition fails to validate the length of certain messages when DHCP logging is enabled. A malformed DHCP message can crash the service, taking down DHCP for clients that depend on it. The flaw only applies when logging is turned on.
Impact
A remote attacker can crash the DHCP Server service, causing a denial of service for hosts relying on it for address assignment. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reachable over the network via the DHCP service (AV:N, AC:L, Au:N per the CVSS 2.0 vector), so no authentication is required. The description ties the flaw to logging being enabled, which is a configuration precondition rather than a user action.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, though EPSS is high (0.72567, 99.4th percentile), suggesting elevated likelihood of attempted exploitation. No public exploit details are given in the record.
What to do
- Apply the Microsoft security update MS04-042 for Windows NT 4.0 Server and Terminal Server Edition.
- If patching is not immediately possible, disable DHCP logging to remove the precondition described in the advisory.
- Restrict network access to the DHCP service to trusted segments where feasible.
- Monitor the DHCP service for unexpected restarts or crashes and treat them as potential exploitation.
Detection
- Watch for unexpected termination or restart of the DHCP Server service on Windows NT 4.0 hosts.
- Alert on malformed or unusually sized DHCP messages reaching the server, especially where logging is enabled.
- Correlate DHCP service crash events with inbound DHCP traffic from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0899 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0899), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.