CVE-2003-0109 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 85.7% (pctl 100)
Patch early
A public exploit exists.
Description
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 85.68% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-03-31 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | windows 2000 |
| microsoft | windows 2000 terminal services |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft IIS 5.0 - WebDAV 'ntdll.dll' Path Overflow (MS03-007) (Metasploit) | 2010-07-25 |
| exploit-db | Microsoft IIS 5.0 - WebDAV Remote Code Execution (3) (xwdav) | 2003-07-08 |
| exploit-db | Microsoft Windows - WebDAV Remote Code Execution (2) | 2003-06-01 |
| exploit-db | Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (3) | 2003-04-04 |
| exploit-db | Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (2) | 2003-03-31 |
| exploit-db | Microsoft IIS 5.0 - WebDAV Remote | 2003-03-24 |
| exploit-db | Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (1) | 2003-03-24 |
| exploit-db | Microsoft IIS - WebDAV 'ntdll.dll' Remote Overflow | 2003-03-23 |
| exploit-db | Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (4) | 2003-03-17 |
References
- http://marc.info/?l=bugtraq&m=104826476427372&w=2
- http://marc.info/?l=bugtraq&m=104861839130254&w=2
- http://marc.info/?l=bugtraq&m=104869293619064&w=2
- http://marc.info/?l=bugtraq&m=104887148323552&w=2
- http://marc.info/?l=bugtraq&m=105768156625699&w=2
- http://marc.info/?l=ntbugtraq&m=104826785731151&w=2
- http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&displaylang=en
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ815021
- http://www.cert.org/advisories/CA-2003-09.html
- http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029
- http://www.iss.net/security_center/static/11533.php
- http://www.kb.cert.org/vuls/id/117394
- http://www.nextgenss.com/papers/ms03-007-ntdll.pdf
- http://www.securityfocus.com/bid/7116
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-007
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A109
- http://marc.info/?l=bugtraq&m=104826476427372&w=2
- http://marc.info/?l=bugtraq&m=104861839130254&w=2
- http://marc.info/?l=bugtraq&m=104869293619064&w=2
- http://marc.info/?l=bugtraq&m=104887148323552&w=2
→ the Explorer · watch your stack · NVD