VDB

CVE-2003-0818

CVE-2003-0818 PUBLISHED KEV CVSS 7.5 HIGH

Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.

EPSS 89.65% · 99.6th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
89.65%
99.6th percentile

Affected Products

VendorProductVersions
microsoftwindows_nt4.0, 4.0, 4.0
microsoftwindows_2003_serverenterprise_64-bit, r2, r2
microsoftwindows_xp
microsoftwindows_2000
n/an/an/a

Timeline

  • Feb 11, 2004 CVE Published
  • Jul 25, 2010 PoC Published
  • Sep 23, 2010 PoC Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›