Vulnerabilities > CVE-2004-0120 - Unspecified vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 3 |
Exploit-Db
description | MS Windows IIS SSL Remote Denial of Service Exploit (MS04-011). CVE-2004-0120. Dos exploit for windows platform |
id | EDB-ID:176 |
last seen | 2016-01-31 |
modified | 2004-04-14 |
published | 2004-04-14 |
reporter | David Barroso |
source | https://www.exploit-db.com/download/176/ |
title | Microsoft Windows IIS - SSL Remote Denial of Service Exploit MS04-011 |
Nessus
NASL family | Windows |
NASL id | MS_KB835732_SSL.NASL |
description | The remote host seems to be running a version of Microsoft SSL library which is vulnerable to several flaws, ranging from a denial of service to remote code executing. Any Microsoft service that utilizes SSL is vulnerable. This includes IIS 4.0, IIS 5.0, IIS 5.1, Exchange Server 5.5, Exchange Server 2000, Exchange Server 2003, and Analysis Services 2000 (included with SQL Server 2000). |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12204 |
published | 2004-04-13 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/12204 |
title | MS04-011: Microsoft Windows SSL Library Malformed Message Remote DoS (835732) (uncredentialed check) |
code |
|
Oval
accepted 2015-08-10T04:01:11.375-04:00 class vulnerability contributors name David Proulx organization The MITRE Corporation name Glenn Strickland organization Secure Elements, Inc. name Maria Mikhno organization ALTX-SOFT
definition_extensions comment Microsoft Windows Server 2003 is installed oval oval:org.mitre.oval:def:128 description The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages. family windows id oval:org.mitre.oval:def:885 status accepted submitted 2004-04-13T12:00:00.000-04:00 title Windows Server 2003 SSL Library Denial of Service version 72 accepted 2015-08-10T04:01:11.507-04:00 class vulnerability contributors name David Proulx organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Glenn Strickland organization Secure Elements, Inc. name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc. name Maria Mikhno organization ALTX-SOFT
definition_extensions comment Microsoft Windows XP (32-bit) is installed oval oval:org.mitre.oval:def:1353 comment Microsoft Windows XP SP1 (32-bit) is installed oval oval:org.mitre.oval:def:1
description The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages. family windows id oval:org.mitre.oval:def:886 status accepted submitted 2004-04-13T12:00:00.000-04:00 title Windows XP SSL Library Denial of Service version 78 accepted 2007-05-23T15:05:54.714-04:00 class vulnerability contributors name David Proulx organization The MITRE Corporation name Glenn Strickland organization Secure Elements, Inc.
description The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages. family windows id oval:org.mitre.oval:def:892 status accepted submitted 2004-04-13T12:00:00.000-04:00 title Windows 2000 SSL Library Denial of Service version 65
References
- http://www.ciac.org/ciac/bulletins/o-114.shtml
- http://www.ciac.org/ciac/bulletins/o-114.shtml
- http://www.kb.cert.org/vuls/id/150236
- http://www.kb.cert.org/vuls/id/150236
- http://www.securityfocus.com/bid/10115
- http://www.securityfocus.com/bid/10115
- http://www.us-cert.gov/cas/techalerts/TA04-104A.html
- http://www.us-cert.gov/cas/techalerts/TA04-104A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15712
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15712
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A885
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A885
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A886
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A886
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A892
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A892