Vulnerability record · CVE-2004-1080 · published 10 January 2005
CVE-2004-1080: Microsoft WINS Service Memory Corruption via Replication Packet
Microsoft · Windows 2000
The WINS service (wins.exe) on Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 mishandles a modified memory pointer in a WINS replication packet, allowing writes to arbitrary memory locations. Because the service runs with high privileges and is reachable over the network, successful corruption can lead to remote code execution.
Description
The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, plus a very high EPSS score, makes this a top-priority exposure wherever the WINS service is still running.
What it is
The WINS service (wins.exe) on Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 mishandles a modified memory pointer in a WINS replication packet, allowing writes to arbitrary memory locations. Because the service runs with high privileges and is reachable over the network, successful corruption can lead to remote code execution.
Impact
A remote attacker can write to arbitrary memory in the WINS service process and potentially execute arbitrary code with the service's privileges, giving full control of the affected server.
Attack surface
Reached over the network by sending a crafted WINS replication packet to TCP port 42; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.798, 99.6th percentile), indicating strong predicted exploitation activity; reference tags include Patch and Vendor Advisory but no public exploit tag.
What to do
- Apply the Microsoft security update for MS04-045 (KB890710) to all affected Windows NT 4.0, Windows 2000, and Windows 2003 servers.
- If WINS is not required, disable or remove the WINS service on affected hosts.
- Block inbound TCP port 42 from untrusted networks at the perimeter and between network segments.
- Restrict WINS replication traffic to only known, trusted WINS partners.
- Retire or isolate end-of-life Windows NT 4.0 and Windows 2000 systems that cannot be patched.
Detection
- Monitor for unexpected inbound connections to TCP port 42 on servers running the WINS service.
- Alert on WINS service crashes, restarts, or abnormal process termination events on affected hosts.
- Inspect network traffic for malformed or unusual WINS replication packets, particularly those with anomalous memory pointer fields.
- Audit WINS replication partner configurations for unauthorized or unexpected peers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-1080 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-1080), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.