VDB
CVE-2003-0533
CVE-2003-0533
PUBLISHED
CVSS 7.5 HIGH
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
EPSS 89.00% · 99.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
89.00%
99.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_me | |
| microsoft | windows_2003_server | r2 |
| microsoft | netmeeting | |
| microsoft | windows_nt | 4.0 |
| n/a | n/a | n/a |
| microsoft | windows_98 | |
| microsoft | windows_xp | |
| microsoft | windows_2000 |
Timeline
- CVE Published
- Jul 3, 2010 PoC Published
- Jul 30, 2010 PoC Published
- Sep 23, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
References
- 20040413 EEYE: Windows Local Security Authority Service Remote Buffer Overflow mailing-list
- O-114 third-party-advisory
- AD20040413C third-party-advisory
- win-lsass-bo(15699) vdb
- oval:org.mitre.oval:def:919 vdb
- MS04-011 vendor-advisory
- oval:org.mitre.oval:def:898 vdb
- oval:org.mitre.oval:def:883 vdb
- TA04-104A third-party-advisory
- 20040429 MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC) mailing-list
- 10108 vdb
- VU#753212 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2003-0533 advisory