CVE-2003-0003 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 43.4% (pctl 99)
Patch early
A public exploit exists.
Description
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 43.39% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-02-07 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| microsoft | windows 2000 |
| microsoft | windows 2000 terminal services |
| microsoft | windows nt |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows 2000/NT 4 - RPC Locator Service Remote Overflow | 2003-04-03 |
| exploit-db | Microsoft Windows XP/2000/NT 4.0 - Locator Service Buffer Overflow | 2003-01-22 |
References
- http://marc.info/?l=bugtraq&m=104394414713415&w=2
- http://marc.info/?l=ntbugtraq&m=104393588232166&w=2
- http://www.cert.org/advisories/CA-2003-03.html
- http://www.kb.cert.org/vuls/id/610986
- http://www.securityfocus.com/bid/6666
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11132
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A103
- http://marc.info/?l=bugtraq&m=104394414713415&w=2
- http://marc.info/?l=ntbugtraq&m=104393588232166&w=2
- http://www.cert.org/advisories/CA-2003-03.html
- http://www.kb.cert.org/vuls/id/610986
- http://www.securityfocus.com/bid/6666
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11132
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A103
→ the Explorer · watch your stack · NVD