← Vulnerability feed

Vulnerability record · CVE-2004-0899 · published 10 January 2005

CVE-2004-0899: Windows NT DHCP Server logging length validation denial of service

Microsoft · Windows Nt

The DHCP Server service in Microsoft Windows NT 4.0 Server and Terminal Server Edition fails to validate the length of certain messages when DHCP logging is enabled. A malformed DHCP message can crash the service, taking down DHCP for clients that depend on it. The flaw only applies when logging is turned on.

5.0 CVSS 2.0 Medium EPSS 73% · top 0.6%
5.0CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw is a remotely reachable denial of service but only affects legacy Windows NT 4.0 systems and requires DHCP logging to be enabled, limiting real-world exposure.

What it is

The DHCP Server service in Microsoft Windows NT 4.0 Server and Terminal Server Edition fails to validate the length of certain messages when DHCP logging is enabled. A malformed DHCP message can crash the service, taking down DHCP for clients that depend on it. The flaw only applies when logging is turned on.

Impact

A remote attacker can crash the DHCP Server service, causing a denial of service for hosts relying on it for address assignment. There is no confidentiality or integrity impact; only availability is affected.

Attack surface

Reachable over the network via the DHCP service (AV:N, AC:L, Au:N per the CVSS 2.0 vector), so no authentication is required. The description ties the flaw to logging being enabled, which is a configuration precondition rather than a user action.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit code, though EPSS is high (0.72567, 99.4th percentile), suggesting elevated likelihood of attempted exploitation. No public exploit details are given in the record.

What to do

  • Apply the Microsoft security update MS04-042 for Windows NT 4.0 Server and Terminal Server Edition.
  • If patching is not immediately possible, disable DHCP logging to remove the precondition described in the advisory.
  • Restrict network access to the DHCP service to trusted segments where feasible.
  • Monitor the DHCP service for unexpected restarts or crashes and treat them as potential exploitation.

Detection

  • Watch for unexpected termination or restart of the DHCP Server service on Windows NT 4.0 hosts.
  • Alert on malformed or unusually sized DHCP messages reaching the server, especially where logging is enabled.
  • Correlate DHCP service crash events with inbound DHCP traffic from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0899 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2004-0210Microsoft Windows POSIX component buffer overflow allows local code executionThe POSIX subsystem in Windows NT and Windows 2000 contains a classic buffer overflow (CWE-120) that can be triggered by local users through crafted …KEVEPSS 7.2%analysed7.8CVE-2002-0367Windows NT/2000 smss.exe debugging subsystem privilege escalationThe smss.exe debugging subsystem in Windows NT and Windows 2000 fails to properly authenticate programs that connect to other programs, allowing a lo…KEVEPSS 4.9%analysed10.0CVE-2005-0050Windows License Logging Service buffer overflow via unvalidated message lengthThe License Logging service in Windows NT Server, Windows 2000 Server and Windows Server 2003 fails to validate the length of messages, producing an …EPSS 47%analysed10.0CVE-2004-0568Microsoft windows 2000 vulnerabilityHyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that…EPSS 35%10.0CVE-2004-0571Microsoft windows 2000 vulnerabilityMicrosoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via…EPSS 31%10.0CVE-2004-0900Microsoft windows nt vulnerabilityThe DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, wh…EPSS 26%10.0CVE-2004-0901Microsoft windows 2000 vulnerabilityMicrosoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote att…EPSS 32%10.0CVE-2004-1080Microsoft WINS Service Memory Corruption via Replication PacketThe WINS service (wins.exe) on Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 mishandles a modified memory pointer in a WINS rep…EPSS 80%analysed

Source: NIST National Vulnerability Database (record CVE-2004-0899), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.