Vulnerabilities > CVE-2003-0528 - Unspecified vulnerability in Microsoft products

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
microsoft
critical
nessus

Summary

Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.

Nessus

  • NASL familyWindows : Microsoft Bulletins
    NASL idSMB_NT_MS03-026.NASL
    descriptionThe remote host is running a version of Windows affected by several vulnerabilities in its RPC interface and RPCSS Service, that could allow an attacker to execute arbitrary code and gain SYSTEM privileges.
    last seen2020-06-01
    modified2020-06-02
    plugin id11790
    published2003-07-17
    reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11790
    titleMS03-026 / MS03-039: Buffer Overrun In RPCSS Service Could Allow Code Execution (823980 / 824146)
  • NASL familyBackdoors
    NASL idSMB_LOGIN_AS_E.NASL
    descriptionIt was possible to log into the remote host with the login
    last seen2020-06-01
    modified2020-06-02
    plugin id11839
    published2003-09-17
    reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11839
    titleMS03-039 Exploitation Backdoor Account Detection
  • NASL familyWindows
    NASL idMSRPC_DCOM2.NASL
    descriptionThe remote host is running a version of Windows that has a flaw in its RPC interface, which may allow an attacker to execute arbitrary code and gain SYSTEM privileges. An attacker or a worm could use it to gain the control of this host. Note that this is NOT the same bug as the one described in MS03-026, which fixes the flaw exploited by the
    last seen2020-06-01
    modified2020-06-02
    plugin id11835
    published2003-09-10
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11835
    titleMS03-039: Microsoft RPC Interface Buffer Overrun (824146) (uncredentialed check)

Oval

  • accepted2011-05-16T04:00:45.782-04:00
    classvulnerability
    contributors
    • nameTiffany Bergeron
      organizationThe MITRE Corporation
    • nameShane Shaffer
      organizationG2, Inc.
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionHeap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.
    familywindows
    idoval:org.mitre.oval:def:127
    statusaccepted
    submitted2003-09-15T12:00:00.000-04:00
    titleRPCSS DCOM Buffer Overflow (Windows 2000)
    version70
  • accepted2011-05-16T04:02:38.527-04:00
    classvulnerability
    contributors
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionHeap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.
    familywindows
    idoval:org.mitre.oval:def:2884
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleRPCSS DCOM Buffer Overflow (XP, SP1)
    version69
  • accepted2005-03-09T07:56:00.000-04:00
    classvulnerability
    contributors
    nameChristine Walzer
    organizationThe MITRE Corporation
    descriptionHeap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.
    familywindows
    idoval:org.mitre.oval:def:2968
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleRPCSS DCOM Buffer Overflow (XP)
    version65
  • accepted2005-03-09T07:56:00.000-04:00
    classvulnerability
    contributors
    nameChristine Walzer
    organizationThe MITRE Corporation
    descriptionHeap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.
    familywindows
    idoval:org.mitre.oval:def:3966
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleRPCSS DCOM Buffer Overflow (Server 2003)
    version66