CVE-2004-0119

The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.

Date published : 2004-04-16

http://www.securityfocus.com/bid/10113

http://www.us-cert.gov/cas/techalerts/TA04-104A.html