← Vulnerability feed

Vulnerability record · CVE-2004-1317 · published 27 December 2004

CVE-2004-1317: Netcat for Windows doexec.c stack buffer overflow via -e option

Netcat for Windows 1.1 contains a stack-based buffer overflow in doexec.c when it runs with the -e option. A long DNS command overflows the buffer and can let a remote attacker execute arbitrary code. The record gives no affected version range beyond the stated 1.1 and no vendor product list.

7.5 CVSS 2.0 High EPSS 60% · top 0.9%
7.5CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code via a long DNS command.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with low attack complexity and a very high EPSS score, though no KEV listing or confirmed public exploit is recorded.

What it is

Netcat for Windows 1.1 contains a stack-based buffer overflow in doexec.c when it runs with the -e option. A long DNS command overflows the buffer and can let a remote attacker execute arbitrary code. The record gives no affected version range beyond the stated 1.1 and no vendor product list.

Impact

A remote attacker can execute arbitrary code in the context of the Netcat process, which typically runs with the privileges of the user who launched it. That can lead to full compromise of the host running the vulnerable listener.

Attack surface

Reachable over the network (AV:N) with no authentication (Au:N) and low complexity (AC:L) per the CVSS 2.0 vector. The flaw is triggered when Netcat is started with the -e option and receives a long DNS command; no user interaction is described.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded. EPSS is high at 0.604 (99.1st percentile), and references include a vendor advisory, but no reference is tagged as exploit code, so public exploit availability is not confirmed by this record.

What to do

  • Upgrade or replace Netcat for Windows 1.1 with a maintained build that fixes the doexec.c overflow.
  • Stop using the -e option; it is the trigger condition for this flaw.
  • Restrict network access to any host running Netcat listeners to trusted sources only.
  • If the tool cannot be replaced, run it under a low-privilege account and isolate it from sensitive networks.

Detection

  • Monitor for Netcat processes launched with the -e flag on Windows hosts.
  • Alert on unusually long DNS command strings or oversized payloads sent to Netcat listeners.
  • Watch for unexpected child processes or command execution spawned by Netcat.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

References

Track CVE-2004-1317 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2004-1317), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.