Oval Definition:oval:org.mitre.oval:def:893
Revision Date:2004-06-16Version:42
Title:Windows 2000 RPCSS DCOM Buffer Overflow (Blaster, Test 3)
Description:A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2003-0813
Platform(s):Microsoft Windows 2000
Product(s):Remote Procedure Call (RPC)
Definition Synopsis
  • Windows 2000 is installed
  • AND the version of rpcrt4.dll is less than 5.0.2195.6904
  • AND NOT the patch kb828741 is installed
  • BACK