Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2003-0715

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Remote Procedure Call (RPC)是Windows 操作系统使用的一种远程过程调用协议,RPC提供进程间交互通信机制,允许在某台计算机上运行程序的无缝地在远程系统上执行代码。协议本身源自开放软件基金会的RPC协议,Microsoft在其基础上增加了自己的一些扩展。 eEye的研究人员发现,由于Windows RPC DCOM接口对报文的长度域缺乏检查导致发生基于堆的溢出,远程攻击者可以利用这些漏洞以本地系统权限在系统上执行任意指令。 漏洞实质上影响的是使用RPC的DCOM接口,此接口处

AI Predicted 10.0 Difficulty: Easy EPSS 40.35% · P99
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2003-0715

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Windows RPC DCOM接口报文长度域堆缓冲区溢出漏洞(MS03-039)
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Remote Procedure Call (RPC)是Windows 操作系统使用的一种远程过程调用协议,RPC提供进程间交互通信机制,允许在某台计算机上运行程序的无缝地在远程系统上执行代码。协议本身源自开放软件基金会的RPC协议,Microsoft在其基础上增加了自己的一些扩展。 eEye的研究人员发现,由于Windows RPC DCOM接口对报文的长度域缺乏检查导致发生基于堆的溢出,远程攻击者可以利用这些漏洞以本地系统权限在系统上执行任意指令。 漏洞实质上影响的是使用RPC的DCOM接口,此接口处
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2003-0715

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2003-0715

登录查看更多情报信息。

Vendor Advisories for CVE-2003-0715 (8)

Mailing List Discussions for CVE-2003-0715 (1)

Same Patch Batch · n/a · 2003-09-12 · 31 CVEs total

CVE-2003-0766 FTP Desktop client多个基于堆的缓冲区溢出漏洞
CVE-2003-0780 Oracle MySQL 缓冲区错误漏洞
CVE-2003-0779 Asterisk CallerID电话详细记录SQL注入漏洞
CVE-2003-0778 SANE后台程序连接用户内存消耗服务拒绝漏洞
CVE-2003-0777 SANE远程调试启用连接终止服务拒绝漏洞
CVE-2003-0776 sane-backends漏洞
CVE-2003-0775 SANE字符串内存配置服务拒绝漏洞
CVE-2003-0774 SANE配线内存泄露漏洞
CVE-2003-0773 SANE SANE_NET_INIT越权访问漏洞
CVE-2003-0772 Progress Software Ipswitch WS_FTP Server 安全漏洞
CVE-2003-0771 Apache::Gallery Gallery.pm漏洞
CVE-2003-0770 IkonBoard FUNC.pm漏洞
CVE-2003-0769 ICQ Web Front guestbook 存在安全漏洞
CVE-2003-0768 Microsoft ASP.Net漏洞
CVE-2003-0767 RogerWilco graphical服务器,Windows dedicated服务器缓冲区溢出漏洞
CVE-2002-1352 Per Magne Knutsen's CartMan shopping cart (cartman.php)漏洞
CVE-2003-0765 N_MIDI.DLL插件3.01漏洞
CVE-2003-0764 Escapade Scripting Engine (ESP)漏洞
CVE-2003-0763 Escapade脚本引擎(ESP)跨站脚本(XSS)漏洞
CVE-2003-0762 Foxweb缓冲区溢出漏洞

Showing top 20 of 31 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2003-0715

No comments yet


Leave a comment