5.1

CVE-2003-0813

A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp2
Microsoft ≫ Windows 2000 Update sp3
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 98 Version -
Microsoft ≫ Windows Nt Version 4.0 Update sp6a SwEdition server
Microsoft ≫ Windows Nt Version 4.0 Update sp6a SwEdition terminal_server
Microsoft ≫ Windows Server 2003 HwPlatform x64
Microsoft ≫ Windows Server 2003 HwPlatform x86
Microsoft ≫ Windows Xp Version -
Microsoft ≫ Windows Xp Version - Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 15.3% 0.964
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011870.html
URL Repurposed
http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011886.html
URL Repurposed
http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011901.html
URL Repurposed
http://marc.info/?l=bugtraq&m=106579825211708&w=2
Third Party Advisory
http://marc.info/?l=bugtraq&m=106588827513795&w=2
Third Party Advisory
http://marc.info/?l=ntbugtraq&m=106580303918155&w=2
Third Party Advisory
http://www.kb.cert.org/vuls/id/547820
Patch
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/8811
Third Party Advisory
Broken Link
VDB Entry
http://www.securitylab.ru/_exploits/rpc2.c.txt
Broken Link
http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Third Party Advisory
US Government Resource
Broken Link
http://xforce.iss.net/xforce/alerts/id/155
Patch
Vendor Advisory
Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012
Patch
Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A893
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A894
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A900
Broken Link