VulnerabilityModified
CVE-2003-0661
The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.
MEDIUM 5.0EPSS 25.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 25.22% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows 2003 server · microsoft/windows nt · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/989932US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3483
- http://www.kb.cert.org/vuls/id/989932US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3483
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.