{ "id": "CVE-2004-0118", "sourceIdentifier": "cve@mitre.org", "published": "2004-06-01T04:00:00.000", "lastModified": "2018-10-12T21:33:56.197", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code." }, { "lang": "es", "value": "El componente del subsistema de la M\u00e1quina Virtual DOS (VDM) en Windows NT 4.0 y Windows 2000 no valida adecuadamente estructuras de sistema, lo que permite a usuarios locales acceder a memoria protegida del kernel y ejecutar c\u00f3digo de su elecci\u00f3n." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 7.2 }, "baseSeverity": "HIGH", "exploitabilityScore": 3.9, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": true, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*", "matchCriteriaId": "4E545C63-FE9C-4CA1-AF0F-D999D84D2AFD" }, { "vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*", "matchCriteriaId": "E53CDA8E-50A8-4509-B070-CCA5604FFB21" } ] } ] } ], "references": [ { "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020070.html", "source": "cve@mitre.org" }, { "url": "http://www.ciac.org/ciac/bulletins/o-114.shtml", "source": "cve@mitre.org" }, { "url": "http://www.eeye.com/html/Research/Advisories/AD20040413E.html", "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.kb.cert.org/vuls/id/783748", "source": "cve@mitre.org", "tags": [ "Patch", "Third Party Advisory", "US Government Resource" ] }, { "url": "http://www.securityfocus.com/bid/10117", "source": "cve@mitre.org" }, { "url": "http://www.us-cert.gov/cas/techalerts/TA04-104A.html", "source": "cve@mitre.org", "tags": [ "Third Party Advisory", "US Government Resource" ] }, { "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/15714", "source": "cve@mitre.org" }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1512", "source": "cve@mitre.org" }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1718", "source": "cve@mitre.org" } ] }