Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2003-0533

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2003-0533
Last Modified 10 Sep 2008 03:19:32
Published 01 Jun 2004 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2003-0533

Summary

Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.

Vulnerable Systems

Operating System

  • Microsoft Windows 2000

  • Microsoft Windows 2003 Server R2

  • Microsoft Windows 98

  • Microsoft Windows Me

  • Microsoft Windows Nt 4.0

  • Microsoft Windows Xp

Application

  • Microsoft Netmeeting


References

CERT-VN - VU#753212

CERT - TA04-104A

MS - MS04-011

EEYE - AD20040413C

BUGTRAQ - 20040429 MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC)

FULLDISC - 20040413 EEYE: Windows Local Security Authority Service Remote Buffer Overflow

XF - win-lsass-bo(15699)

BID - 10108

CIAC - O-114


Last Updated: 27 May 2016 10:37:57