Oval Definition:oval:org.mitre.oval:def:894
Revision Date:2014-07-14Version:44
Title:Server 2003 RPCSS DCOM Buffer Overflow
Description:A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2003-0813
Platform(s):Microsoft Windows Server 2003
Product(s):Remote Procedure Call (RPC)
Definition Synopsis
  • Microsoft Windows Server 2003 is installed
  • AND a vulnerable version of rpcrt4.dll exists on Server 2003
  • machine has followed the GDR update path and rpcrt4.dll is less than 5.2.3790.137
  • OR machine has followed the QFE update path and rpcrt4.dll is less than 5.2.3790.141
  • BACK