CVE-2003-0910 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 26.1% (pctl 98)
Patch early
A public exploit exists.
Description
The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 26.14% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-06-01 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | windows 2000 |
| microsoft | windows nt |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows NT 4.0/2000 - Local Descriptor Table Privilege Escalation (MS04-011) | 2004-04-18 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html
- http://www.ciac.org/ciac/bulletins/o-114.shtml
- http://www.eeye.com/html/Research/Advisories/AD20040413D.html
- http://www.kb.cert.org/vuls/id/122076
- http://www.securityfocus.com/bid/10122
- http://www.us-cert.gov/cas/techalerts/TA04-104A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15707
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A890
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A911
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html
- http://www.ciac.org/ciac/bulletins/o-114.shtml
- http://www.eeye.com/html/Research/Advisories/AD20040413D.html
- http://www.kb.cert.org/vuls/id/122076
- http://www.securityfocus.com/bid/10122
- http://www.us-cert.gov/cas/techalerts/TA04-104A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15707
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A890
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A911
→ the Explorer · watch your stack · NVD