CVE-2004-0124
Description
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Object Identity Vulnerability in Microsoft Windows DCOM RPC allows remote attackers to discover object identifiers, potentially enabling unauthorized network communication.
Vulnerability
The Object Identity Vulnerability (CVE-2004-0124) exists in the DCOM RPC interface of Microsoft Windows NT 4.0, 2000, XP, and Server 2003. The issue is that the COM (Component Object Model) component creates object identifiers in a predictable manner, allowing an attacker to discover valid object identifiers via a specially crafted "alter context" call containing additional data. Affected versions include Windows NT 4.0 SP6a, Windows 2000 SP2-SP4, Windows XP (including SP1 and 64-Bit Edition), and Windows Server 2003 [1][3].
Exploitation
An attacker can exploit this vulnerability by sending a crafted DCOM RPC request to a target system. The attacker does not require authentication but needs network access to the target. By manipulating the "alter context" call with additional data, the attacker can enumerate valid object identifiers. This information can then be used to trigger the system to open network communication ports that were previously closed or filtered [3].
Impact
Successful exploitation allows an attacker to discover object identifiers, potentially leading to information disclosure about the system. Moreover, the attacker can cause applications to open and communicate over alternate or unexpected ports, bypassing security policies and potentially enabling further attacks. The vulnerability does not directly grant code execution but can facilitate network-based attacks [1][3].
Mitigation
Microsoft released security bulletin MS04-012 on April 13, 2004, providing updates for all affected Windows versions. Customers are recommended to apply the update immediately [1]. No workarounds are documented in the available references. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog as of the publication date.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
11cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*
- (no CPE)
cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*
- (no CPE)
cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:4.0:*:server:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:4.0:*:terminal_server:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:4.0:*:workstation:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:gold:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_xp:*:gold:*:*:*:*:*:*
- (no CPE)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- www.kb.cert.org/vuls/id/212892nvdPatchThird Party AdvisoryUS Government Resource
- www.us-cert.gov/cas/techalerts/TA04-104A.htmlnvdThird Party AdvisoryUS Government Resource
- secunia.com/advisories/11065/nvd
- www.ciac.org/ciac/bulletins/o-115.shtmlnvd
- www.securityfocus.com/bid/10121nvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/15711nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1041nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1062nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1066nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1072nvd
News mentions
0No linked articles in our index yet.