CVE-2003-0819
Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 40.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 40.87% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- microsoft/proxy server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/10611
- http://www.cert.org/advisories/CA-2004-01.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/749342Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/9406
- http://www.securityfocus.com/bid/9408Patch, Vendor Advisory
- http://www.securitytracker.com/id?1008698
- http://www.uniras.gov.uk/vuls/2004/006489/h323.htm
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-001
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A478
- http://secunia.com/advisories/10611
- http://www.cert.org/advisories/CA-2004-01.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/749342Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/9406
- http://www.securityfocus.com/bid/9408Patch, Vendor Advisory
- http://www.securitytracker.com/id?1008698
- http://www.uniras.gov.uk/vuls/2004/006489/h323.htm
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-001
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A478
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.