VDB
CVE-2003-0109
CVE-2003-0109
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
EPSS 88.71% · 99.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
88.71%
99.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | *, n/a |
| microsoft | windows_2000_terminal_services | |
| microsoft | windows_2000 |
Timeline
- Mar 18, 2003 CVE Published
- Sep 7, 2007 VulnCheck KEV Exploitation
- Jul 25, 2010 PoC Published
- Jul 30, 2010 PoC Published
- Sep 23, 2010 PoC Published
- Jun 20, 2017 VulnCheck KEV Exploitation
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
References
- 20030326 WebDAV exploit: using wide character decoder scheme mailing-list
- 20030321 New attack vectors and a vulnerability dissection of MS03-007 mailing-list
- oval:org.mitre.oval:def:109 vdb
- 20030325 IIS 5.0 WebDAV -Proof of concept-. Fully documented. mailing-list
- http://www.nextgenss.com/papers/ms03-007-ntdll.pdf url
- http-webdav-long-request(11533) vdb
- Q815021 vendor-advisory
- 20030317 Microsoft IIS WebDAV Remote Compromise Vulnerability third-party-advisory
- 20030328 Fate Research Labs Presents: Analysis of the NTDLL.DLL Exploit mailing-list
- 7116 vdb
- http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&displaylang=en url
- 20030708 WDAV exploit without netcat and with pretty magic number mailing-list
- 20030321 New attack vectors and a vulnerability dissection of MS03-007 mailing-list
- MS03-007 vendor-advisory
- VU#117394 third-party-advisory
- CA-2003-09 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2003-0109 advisory
- http://support.microsoft.com/default.aspx?scid=kb;[LN];Q815021 url