Vulnerabilities > CVE-2003-0715 - Unspecified vulnerability in Microsoft products

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
microsoft
critical
nessus

Summary

Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.

Nessus

  • NASL familyWindows : Microsoft Bulletins
    NASL idSMB_NT_MS03-026.NASL
    descriptionThe remote host is running a version of Windows affected by several vulnerabilities in its RPC interface and RPCSS Service, that could allow an attacker to execute arbitrary code and gain SYSTEM privileges.
    last seen2020-06-01
    modified2020-06-02
    plugin id11790
    published2003-07-17
    reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11790
    titleMS03-026 / MS03-039: Buffer Overrun In RPCSS Service Could Allow Code Execution (823980 / 824146)
  • NASL familyWindows
    NASL idMSRPC_DCOM2.NASL
    descriptionThe remote host is running a version of Windows that has a flaw in its RPC interface, which may allow an attacker to execute arbitrary code and gain SYSTEM privileges. An attacker or a worm could use it to gain the control of this host. Note that this is NOT the same bug as the one described in MS03-026, which fixes the flaw exploited by the
    last seen2020-06-01
    modified2020-06-02
    plugin id11835
    published2003-09-10
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11835
    titleMS03-039: Microsoft RPC Interface Buffer Overrun (824146) (uncredentialed check)

Oval

  • accepted2005-03-09T07:56:00.000-04:00
    classvulnerability
    contributors
    nameChristine Walzer
    organizationThe MITRE Corporation
    descriptionHeap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.
    familywindows
    idoval:org.mitre.oval:def:1202
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleWindows Server 2003 (64-bit) RPCSS DCOM Buffer Overflow (Blaster)
    version66
  • accepted2011-05-16T04:01:53.390-04:00
    classvulnerability
    contributors
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionHeap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.
    familywindows
    idoval:org.mitre.oval:def:1813
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleWindows XP (32-bit, SP1) RPCSS DCOM Buffer Overflow (Blaster)
    version69
  • accepted2005-06-29T06:49:00.000-04:00
    classvulnerability
    contributors
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    descriptionHeap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.
    familywindows
    idoval:org.mitre.oval:def:20
    statusdeprecated
    submitted2004-11-02T12:00:00.000-04:00
    titleSuppressed OVAL20
    version65
  • accepted2011-05-16T04:02:34.353-04:00
    classvulnerability
    contributors
    • nameTiffany Bergeron
      organizationThe MITRE Corporation
    • nameShane Shaffer
      organizationG2, Inc.
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionHeap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.
    familywindows
    idoval:org.mitre.oval:def:264
    statusaccepted
    submitted2003-12-03T12:00:00.000-04:00
    titleWindows 2000 RPCSS DCOM Buffer Overflow (Blaster, Test 1)
    version70
  • accepted2005-03-09T07:56:00.000-04:00
    classvulnerability
    contributors
    nameChristine Walzer
    organizationThe MITRE Corporation
    descriptionHeap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.
    familywindows
    idoval:org.mitre.oval:def:4224
    statusaccepted
    submitted2005-01-18T12:00:00.000-04:00
    titleWindows XP (32-bit) RPCSS DCOM Buffer Overflow (Blaster)
    version65