CVE-2003-0111 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 36.7% (pctl 98)
Patch early
A public exploit exists.
Description
The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 36.67% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-05-05 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | virtual machine |
| microsoft | windows 2000 |
| microsoft | windows 2000 terminal services |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Java Virtual Machine 3802 Series - Bytecode Verifier | 2002-11-21 |
References
- http://www.iss.net/security_center/static/11751.php
- http://www.kb.cert.org/vuls/id/447569
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-011
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A136
- http://www.iss.net/security_center/static/11751.php
- http://www.kb.cert.org/vuls/id/447569
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-011
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A136
→ the Explorer · watch your stack · NVD