peter bassill · operator
$ cve CVE-2003-0818 JSON

CVE-2003-0818 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 82.2% (pctl 100)

Patch early

A public exploit exists.

Description

Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS82.24% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2004-03-03
Last modified2026-06-16

Affected (4)

VendorProduct
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows nt
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD