peter bassill · operator
$ cve CVE-2003-0717 JSON

CVE-2003-0717 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 61% (pctl 99)

Patch early

A public exploit exists.

Description

The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS61% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2003-11-17
Last modified2026-06-16

Affected (5)

VendorProduct
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows me
microsoftwindows nt
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD