Vulnerabilities > CVE-2003-0112 - Buffer Overflow vulnerability in Microsoft Windows Kernel Message Handling

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
microsoft
nessus

Summary

Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.

Nessus

NASL familyWindows : Microsoft Bulletins
NASL idSMB_NT_MS03-013.NASL
descriptionThe remote version of Windows has a flaw in the way the kernel passes error messages to a debugger. An attacker could exploit it to gain elevated privileges on this host. To successfully exploit this vulnerability, an attacker would need a local account on this host.
last seen2020-06-01
modified2020-06-02
plugin id11541
published2003-04-16
reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11541
titleMS03-013: Buffer Overrun in Windows Kernel Message Handling could Lead to Elevated Privileges (811493)

Oval

  • accepted2011-05-16T04:00:44.313-04:00
    classvulnerability
    contributors
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionBuffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
    familywindows
    idoval:org.mitre.oval:def:1264
    statusaccepted
    submitted2005-01-31T12:00:00.000-04:00
    titleWindows XP Kernel Debugger-based Buffer Overflow (Test 1)
    version70
  • accepted2005-06-29T06:49:00.000-04:00
    classvulnerability
    contributors
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameJonathan Baker
      organizationThe MITRE Corporation
    definition_extensions
    commentMicrosoft Windows NT is installed
    ovaloval:org.mitre.oval:def:36
    descriptionBuffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
    familywindows
    idoval:org.mitre.oval:def:142
    statusdeprecated
    submitted2004-11-02T12:00:00.000-04:00
    titleSuppressed OVAL142, covered by OVAL2022
    version71
  • accepted2008-03-24T04:00:20.925-04:00
    classvulnerability
    contributors
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameJonathan Baker
      organizationThe MITRE Corporation
    definition_extensions
    commentMicrosoft Windows NT is installed
    ovaloval:org.mitre.oval:def:36
    descriptionBuffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
    familywindows
    idoval:org.mitre.oval:def:2022
    statusaccepted
    submitted2004-07-13T12:00:00.000-04:00
    titleWindows NT Kernel Debugger-based Buffer Overflow
    version72
  • accepted2008-03-24T04:00:23.681-04:00
    classvulnerability
    contributors
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameJonathan Baker
      organizationThe MITRE Corporation
    definition_extensions
    commentMicrosoft Windows NT is installed
    ovaloval:org.mitre.oval:def:36
    descriptionBuffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
    familywindows
    idoval:org.mitre.oval:def:2265
    statusaccepted
    submitted2004-07-13T12:00:00.000-04:00
    titleWindows NT Terminal Server Kernel Debugger-based Buffer Overflow
    version72
  • accepted2005-06-29T06:49:00.000-04:00
    classvulnerability
    contributors
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    descriptionBuffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
    familywindows
    idoval:org.mitre.oval:def:262
    statusaccepted
    submitted2004-11-02T12:00:00.000-04:00
    titleWindows 2000 Kernel Debugger-based Buffer Overflow
    version65
  • accepted2005-06-29T06:49:00.000-04:00
    classvulnerability
    contributors
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    descriptionBuffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
    familywindows
    idoval:org.mitre.oval:def:3145
    statusaccepted
    submitted2004-07-13T12:00:00.000-04:00
    titleWindows 2000 Kernel Debugger-based Buffer Overflow
    version65
  • accepted2011-05-16T04:03:27.460-04:00
    classvulnerability
    contributors
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameShane Shaffer
      organizationG2, Inc.
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionBuffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
    familywindows
    idoval:org.mitre.oval:def:779
    statusaccepted
    submitted2004-11-30T12:00:00.000-04:00
    titleWindows XP Kernel Debugger-based Buffer Overflow (Test 2)
    version70