MS04-006: WINS Server Remote Overflow (830352)

Critical Nessus Plugin ID 12051


Arbitrary code can be executed on the remote host.


The remote Windows Internet Naming Service (WINS) is vulnerable to a flaw that could allow an attacker to execute arbitrary code on this host.

To exploit this flaw, an attacker would need to send a specially crafted packet with improperly advertised lengths.


Microsoft has released a set of patches for Windows NT, 2000 and 2003.

See Also

Plugin Details

Severity: Critical

ID: 12051

File Name: smb_nt_ms04-006.nasl

Version: $Revision: 1.39 $

Type: local

Agent: windows

Published: 2004/02/10

Modified: 2017/07/14

Dependencies: 13855, 57033

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2004/02/10

Vulnerability Publication Date: 2004/02/10

Reference Information

CVE: CVE-2003-0825

BID: 9624

OSVDB: 3903

MSFT: MS04-006

MSKB: 830352

CWE: 20