CVE Vulnerabilities

CVE-2004-0894

Published: Jan 10, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.

Affected Software

NameVendorStart VersionEnd Version
Windows_2000Microsoft**
Windows_2003_serverMicrosoftdatacenter_64-bit-sp1_beta_1 (including)datacenter_64-bit-sp1_beta_1 (including)
Windows_2003_serverMicrosoftenterprise (including)enterprise (including)
Windows_2003_serverMicrosoftenterprise-sp1_beta_1 (including)enterprise-sp1_beta_1 (including)
Windows_2003_serverMicrosoftenterprise_64-bit (including)enterprise_64-bit (including)
Windows_2003_serverMicrosoftenterprise_64-bit-sp1_beta_1 (including)enterprise_64-bit-sp1_beta_1 (including)
Windows_2003_serverMicrosoftr2 (including)r2 (including)
Windows_2003_serverMicrosoftr2-sp1_beta_1 (including)r2-sp1_beta_1 (including)
Windows_2003_serverMicrosoftstandard (including)standard (including)
Windows_2003_serverMicrosoftstandard-sp1_beta_1 (including)standard-sp1_beta_1 (including)
Windows_2003_serverMicrosoftweb (including)web (including)
Windows_2003_serverMicrosoftweb-sp1_beta_1 (including)web-sp1_beta_1 (including)
Windows_xpMicrosoft**

References