← Back

CVE-2003-0352

nvd nist
Published: Aug 18, 2003Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.

Affected (48)

4 products
Windows 2000
Windows 2003 Server
Windows Nt
Windows Xp
Configuration A
48 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
All versions
All versions
All versions
All versions
Microsoft
Version enterprise
Version enterprise_64-bit
Version r2
Version r2
Version standard
Version web
Microsoft
Version 4.0
Version 4.0
Version 4.0
Version 4.0
Version 4.0 sp1
Version 4.0 sp1
Version 4.0 sp1
Version 4.0 sp1
Version 4.0 sp2
Version 4.0 sp2
Version 4.0 sp2
Version 4.0 sp2
Version 4.0 sp3
Version 4.0 sp3
Version 4.0 sp3
Version 4.0 sp3
Version 4.0 sp4
Version 4.0 sp4
Version 4.0 sp4
Version 4.0 sp4
Version 4.0 sp5
Version 4.0 sp5
Version 4.0 sp5
Version 4.0 sp5
Version 4.0 sp6
Version 4.0 sp6
Version 4.0 sp6
Version 4.0 sp6
Version 4.0 sp6a
Version 4.0 sp6a
Version 4.0 sp6a
Version 4.0 sp6a
Microsoft
All versions
All versions
All versions
All versions
All versions

References (28)

Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.