CVE-2003-0813
A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 16.96% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-367
- Affected
- microsoft/windows 2000 · microsoft/windows 98 · microsoft/windows nt · microsoft/windows server 2003 · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011870.htmlURL Repurposed
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011886.htmlURL Repurposed
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011901.htmlURL Repurposed
- http://marc.info/?l=bugtraq&m=106579825211708&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=106588827513795&w=2Third Party Advisory
- http://marc.info/?l=ntbugtraq&m=106580303918155&w=2Third Party Advisory
- http://www.kb.cert.org/vuls/id/547820Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/8811Broken Link, Third Party Advisory, VDB Entry
- http://www.securitylab.ru/_exploits/rpc2.c.txtBroken Link
- http://www.us-cert.gov/cas/techalerts/TA04-104A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://xforce.iss.net/xforce/alerts/id/155Broken Link, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A893Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A894Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A900Broken Link
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011870.htmlURL Repurposed
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011886.htmlURL Repurposed
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011901.htmlURL Repurposed
- http://marc.info/?l=bugtraq&m=106579825211708&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=106588827513795&w=2Third Party Advisory
- http://marc.info/?l=ntbugtraq&m=106580303918155&w=2Third Party Advisory
- http://www.kb.cert.org/vuls/id/547820Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/8811Broken Link, Third Party Advisory, VDB Entry
- http://www.securitylab.ru/_exploits/rpc2.c.txtBroken Link
- http://www.us-cert.gov/cas/techalerts/TA04-104A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://xforce.iss.net/xforce/alerts/id/155Broken Link, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A893Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A894Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A900Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.