ZeroHour

CVE-2004-0210

KEVmass

Local Privilege Escalation via Buffer Overflow in Microsoft Windows POSIX Subsystem

CISA: Microsoft Windows Privilege Escalation Vulnerability

CVSS
EPSS
7%p94
Published
KEV added
AI analysis

CVE-2004-0210 is a memory-safety flaw (CWE-120, buffer overflow) in the POSIX subsystem of Microsoft Windows that allows a user who is already logged on to elevate privileges and take complete control of the affected system. It is triggered by a local, logged-on user sending crafted input to the POSIX subsystem, so exploitation requires the ability to execute code on the host rather than network access. A successful attacker gains SYSTEM-level control, fully compromising the machine and typically using the escalation to turn a limited account into full administrative access as part of a broader intrusion or ransomware chain. The flaw affects Windows versions that shipped the vulnerable POSIX subsystem — historically Windows NT 4.0, Windows 2000, and Windows XP per Microsoft's MS04-020 bulletin — while CISA lists the affected product broadly as 'Microsoft Windows'. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2022-03-03, confirming exploitation in the wild (ransomware use unknown); EPSS estimates a 7.2% probability of exploitation within 30 days (94th percentile), no public proof-of-concept is known, and CVSS has not yet been scored.

What to do: Apply Microsoft's POSIX subsystem security update (MS04-020) per vendor instructions on any Windows NT 4.0, Windows 2000, or Windows XP system still in service, prioritizing multi-user hosts such as terminal servers, shared workstations, and jump boxes where untrusted users can log on locally. Federal agencies must remediate per CISA's KEV/BOD 22-01 timelines; where legacy systems cannot be patched, restrict interactive logon to trusted users, disable or remove the POSIX subsystem if unused, and monitor for signs of local SYSTEM-level escalation.

Affected
Microsoft Windows (POSIX subsystem)CISA lists 'Microsoft Windows' broadly; the vulnerable POSIX subsystem shipped in Windows NT 4.0, Windows 2000, and Windows XP (per Microsoft bulletin MS04-020)
Estimated exposure
masstens of millions of legacy Windows installs (NT 4.0/2000/XP era), of which only hosts allowing untrusted local logon are practically exposed — Based on the residual installed base of legacy Windows — Windows XP alone still ran on an estimated tens of millions of machines into the 2020s (roughly 1% of the global Windows PC base), plus Windows NT 4.0/2000 persisting in embedded and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Windows
Weakness
CWE-120

In the news