[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2003-0533Date: (C)2004-06-01   (M)2023-12-22


Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-10108
http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020069.html
http://marc.info/?l=bugtraq&m=108325860431471&w=2
AD20040413C
MS04-011
O-114
TA04-104A
VU#753212
win-lsass-bo(15699)

CPE    6
cpe:/o:microsoft:windows_nt:4.0:sp6a
cpe:/o:microsoft:windows_xp::sp1:tablet_pc
cpe:/o:microsoft:windows_me
cpe:/o:microsoft:windows_98::gold
...
OVAL    3
oval:org.mitre.oval:def:898
oval:org.mitre.oval:def:919
oval:org.mitre.oval:def:883

© SecPod Technologies