CVE-2004-0210Active Exploitation(microsoft / interix)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft interix systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-03-24. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-120

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • interix
  • windows_2000
  • windows_nt

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
interixwindows_2000windows_nt

3 versions affected across 3 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-30: 2PoC Mentioned / Linked · 2026-04-30: 1Exploit Tool / Code · 2026-04-30: 1Active Exploitation · 2026-04-30: 2Patch / Workaround · 2026-04-30: 104-30
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2004-0210 disclosed. CISA: CVE-2004-0210 added to Known Exploited Vulnerabilities — Microsoft Windows Status: ✅ Confirmed exploited in the wild Date added: 2022-03-03 Required action: Apply updates per vendor instructions.

    Post summary

    The post confirms that CVE-2004-0210 is actively exploited in the wild, as per CISA’s known exploited vulnerabilities list, and urges applying vendor-provided updates.

    1000035
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2004-0210-windows #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked research notes an active exploitation of CVE‑2004‑0210 on Windows, likely presenting PoC code and hinting at real‑world usage, but does not mention mitigating patches or provide detailed technical analysis.

    0000017
    128 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftinterix2.2--
OSmicrosoftwindows_2000---
OSmicrosoftwindows_2000---
OSmicrosoftwindows_2000---
OSmicrosoftwindows_nt4.0--
OSmicrosoftwindows_nt4.0--
OSmicrosoftwindows_nt4.0--

Explore more