CVE-2003-0818
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 82%
from disclosure to weapon3 days
Published on NVDFeb 11
1st PoC+3d
metasploitFeb 10
exploitation probability
82%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/153unverifiedexploitdbwww.exploit-db.com/exploits/16377unverifiedexploitdbwww.exploit-db.com/exploits/3022unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=107643836125615&w=2http://marc.info/?l=bugtraq&m=107643892224825&w=2http://marc.info/?l=ntbugtraq&m=107650972617367&w=2http://marc.info/?l=ntbugtraq&m=107650972723080&w=2https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-007https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A653https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A796https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A797https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A799http://www.kb.cert.org/vuls/id/216324http://www.kb.cert.org/vuls/id/583108http://www.us-cert.gov/cas/techalerts/TA04-041A.html