Vulnerability record · CVE-2004-2271 · published 31 December 2004
CVE-2004-2271: MiniShare HTTP server buffer overflow via long GET request
MMinishare · Minimal Http Server
MiniShare 1.4.1 and earlier contains a buffer overflow that is triggered by a long HTTP GET request. A remote, unauthenticated attacker can send an oversized request to crash the server or execute arbitrary code in its context. The flaw is in an end-of-life minimal HTTP server, so exposure persists wherever the product is still deployed.
Description
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with public exploit references and very high EPSS, though the product is old and likely limited in deployment.
What it is
MiniShare 1.4.1 and earlier contains a buffer overflow that is triggered by a long HTTP GET request. A remote, unauthenticated attacker can send an oversized request to crash the server or execute arbitrary code in its context. The flaw is in an end-of-life minimal HTTP server, so exposure persists wherever the product is still deployed.
Impact
An attacker gains remote code execution on the host running MiniShare, or at minimum can crash the service. Successful exploitation typically yields the privileges of the MiniShare process.
Attack surface
Reachable over the network through the HTTP listener; the CVSS vector AV:N/AC:L/Au:N confirms no authentication is required. No user interaction is needed because the attacker sends the malicious GET request directly to the server.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.72 (99th percentile) and multiple references are tagged Exploit, indicating public exploit code exists. No ransomware group usage is documented in the record.
What to do
- Upgrade MiniShare to a version later than 1.4.1, or retire the product if no supported release exists.
- If the server must remain, restrict access to trusted networks and block untrusted inbound traffic to its HTTP port.
- Run the service under a low-privilege account and isolate it so code execution does not reach sensitive data or systems.
- Monitor vendor and OSVDB patch references for any backported fix and apply it promptly.
Detection
- Inspect HTTP server logs for abnormally long GET request lines or oversized request URIs targeting the MiniShare port.
- Alert on MiniShare process crashes or restarts, which can indicate overflow attempts.
- Watch for unexpected child processes or outbound connections originating from the MiniShare host after HTTP requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-2271 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-2271), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.