CVE-2003-0717 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 61% (pctl 99)
Patch early
A public exploit exists.
Description
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 61% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-11-17 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| microsoft | windows 2000 |
| microsoft | windows 2003 server |
| microsoft | windows me |
| microsoft | windows nt |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Messenger (Linux) - Denial of Service (MS03-043) | 2004-08-08 |
| exploit-db | Microsoft Windows Messenger Service (French) - Remote (MS03-043) | 2003-12-16 |
| exploit-db | Microsoft Windows XP/2000 - Messenger Service Buffer Overrun (MS03-043) | 2003-10-25 |
| exploit-db | Microsoft Windows Messenger Service - Denial of Service (MS03-043) | 2003-10-18 |
References
- http://marc.info/?l=bugtraq&m=106666713812158&w=2
- http://marc.info/?l=ntbugtraq&m=106632188709562&w=2
- http://www.cert.org/advisories/CA-2003-27.html
- http://www.kb.cert.org/vuls/id/575892
- http://www.securityfocus.com/bid/8826
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-043
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A213
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A268
- http://marc.info/?l=bugtraq&m=106666713812158&w=2
- http://marc.info/?l=ntbugtraq&m=106632188709562&w=2
- http://www.cert.org/advisories/CA-2003-27.html
- http://www.kb.cert.org/vuls/id/575892
- http://www.securityfocus.com/bid/8826
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-043
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A213
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A268
→ the Explorer · watch your stack · NVD