CVE-2003-0352
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 98%
from disclosure to weapon25 days
Published on NVDJul 17
1st PoC+25d
metasploitJul 16
VulnCheck+1513d
exploitation probability
98%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16749exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/100exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/22917⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007079.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007357.htmlhttp://marc.info/?l=bugtraq&m=105838687731618&w=2http://marc.info/?l=bugtraq&m=105914789527294&w=2https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-026https://exchange.xforce.ibmcloud.com/vulnerabilities/12629https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A194https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2343https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A296http://www.cert.org/advisories/CA-2003-16.htmlhttp://www.cert.org/advisories/CA-2003-19.htmlhttp://www.kb.cert.org/vuls/id/568148