peter bassill · operator
$ cve CVE-2003-0533 JSON

CVE-2003-0533 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 85.5% (pctl 100)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS85.49% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2004-06-01
Last modified2026-06-16

Affected (7)

VendorProduct
microsoftnetmeeting
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows 98
microsoftwindows me
microsoftwindows nt
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD