CVE-2003-0003
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 43.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 43.39% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 terminal services · microsoft/windows 2000 · microsoft/windows nt · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=104394414713415&w=2Third Party Advisory
- http://marc.info/?l=ntbugtraq&m=104393588232166&w=2Third Party Advisory
- http://www.cert.org/advisories/CA-2003-03.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/610986Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/6666Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11132Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A103Third Party Advisory
- http://marc.info/?l=bugtraq&m=104394414713415&w=2Third Party Advisory
- http://marc.info/?l=ntbugtraq&m=104393588232166&w=2Third Party Advisory
- http://www.cert.org/advisories/CA-2003-03.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/610986Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/6666Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11132Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A103Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.