CVE-2003-0109
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 86%
from disclosure to weapon0 days
Published on NVDMar 18
1st PoCMar 17
metasploit+73d
VulnCheck+5208d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesVulnCheck
9 public exploit(s)
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
Affected products
n/a · n/apublic PoCs found — 9
exploitdbwww.exploit-db.com/exploits/1unverifiedexploitdbwww.exploit-db.com/exploits/22365unverifiedexploitdbwww.exploit-db.com/exploits/22366unverifiedexploitdbwww.exploit-db.com/exploits/22367unverifiedexploitdbwww.exploit-db.com/exploits/22368unverifiedexploitdbwww.exploit-db.com/exploits/16470unverifiedexploitdbwww.exploit-db.com/exploits/2unverifiedexploitdbwww.exploit-db.com/exploits/51unverifiedexploitdbwww.exploit-db.com/exploits/36unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=104826476427372&w=2http://marc.info/?l=bugtraq&m=104861839130254&w=2http://marc.info/?l=bugtraq&m=104869293619064&w=2http://marc.info/?l=bugtraq&m=104887148323552&w=2http://marc.info/?l=bugtraq&m=105768156625699&w=2http://marc.info/?l=ntbugtraq&m=104826785731151&w=2http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&displaylang=enhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-007https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A109http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ815021http://www.cert.org/advisories/CA-2003-09.htmlhttp://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029