VDB
CVE-2003-0349
CVE-2003-0349
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.
EPSS 88.21% · 99.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
88.21%
99.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| microsoft | windows_2000 |
Timeline
- Jun 28, 2003 CVE Published
- Jul 25, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
References
- 20030626 Windows Media Services Remote Command Execution #2 mailing-list
- 9115 third-party-advisory
- VU#113716 third-party-advisory
- oval:org.mitre.oval:def:938 vdb
- MS03-022 vendor-advisory
- 20030626 Windows Media Services Remote Command Execution #2 mailing-list
- 1007059 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2003-0349 advisory