Unrated severityNVD Advisory· Published Jul 7, 2004· Updated Jun 16, 2026
CVE-2004-0420
CVE-2004-0420
Description
The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:6.0.2800.1106:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
14- www.securityfocus.com/archive/1/351379nvdExploitVendor Advisory
- www.securityfocus.com/bid/9510nvdExploitVendor Advisory
- www.kb.cert.org/vuls/id/106324nvdUS Government Resource
- www.us-cert.gov/cas/techalerts/TA04-196A.htmlnvdUS Government Resource
- secunia.com/advisories/10736/nvd
- www.security-express.com/archives/bugtraq/2004-01/0300.htmlnvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-024nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/14964nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2245nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2381nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2894nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3386nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3533nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3604nvd
News mentions
0No linked articles in our index yet.