Vulnerability record · CVE-2004-1317 · published 27 December 2004
CVE-2004-1317: Netcat for Windows doexec.c stack buffer overflow via -e option
Netcat for Windows 1.1 contains a stack-based buffer overflow in doexec.c when it runs with the -e option. A long DNS command overflows the buffer and can let a remote attacker execute arbitrary code. The record gives no affected version range beyond the stated 1.1 and no vendor product list.
Description
Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code via a long DNS command.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with low attack complexity and a very high EPSS score, though no KEV listing or confirmed public exploit is recorded.
What it is
Netcat for Windows 1.1 contains a stack-based buffer overflow in doexec.c when it runs with the -e option. A long DNS command overflows the buffer and can let a remote attacker execute arbitrary code. The record gives no affected version range beyond the stated 1.1 and no vendor product list.
Impact
A remote attacker can execute arbitrary code in the context of the Netcat process, which typically runs with the privileges of the user who launched it. That can lead to full compromise of the host running the vulnerable listener.
Attack surface
Reachable over the network (AV:N) with no authentication (Au:N) and low complexity (AC:L) per the CVSS 2.0 vector. The flaw is triggered when Netcat is started with the -e option and receives a long DNS command; no user interaction is described.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded. EPSS is high at 0.604 (99.1st percentile), and references include a vendor advisory, but no reference is tagged as exploit code, so public exploit availability is not confirmed by this record.
What to do
- Upgrade or replace Netcat for Windows 1.1 with a maintained build that fixes the doexec.c overflow.
- Stop using the -e option; it is the trigger condition for this flaw.
- Restrict network access to any host running Netcat listeners to trusted sources only.
- If the tool cannot be replaced, run it under a low-privilege account and isolate it from sensitive networks.
Detection
- Monitor for Netcat processes launched with the -e flag on Windows hosts.
- Alert on unusually long DNS command strings or oversized payloads sent to Netcat listeners.
- Watch for unexpected child processes or command execution spawned by Netcat.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
References
Track CVE-2004-1317 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2004-1317), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.