CVE-2004-0116 describes a denial-of-service vulnerability in the RPCSS Service's DCOM activation function affecting Microsoft Windows 2000, XP, and 2003. An unauthenticated remote attacker can exploit this by sending an activation request with an oversized length field, leading to excessive memory consumption and system instability. While the CVSS score is 5.0 (medium severity) due to its remote, low-complexity attack vector and partial availability impact, its FAUCET Risk Score of 97/100 indicates a higher perceived risk. There is no public exploit code available, and it is not listed in CISA's KEV catalog, though it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:*:gold:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.