CVE-2003-0659
Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.
- Affected products
- User32.Dll, Windows Nt, Windows Server 2003
- Microsoft Windows 2000
- All versions
- Microsoft Windows 2003 Server
- = enterprise, enterprise_64-bit, R2, standard, web
- Microsoft Windows Nt
- = 4.0
- Microsoft Windows Xp
- All versions
- CVSS 2.0
- 7.2 HIGH
- EPSS
- 43.0% (99th percentile)
- NVD status
- Modified
- Published
- 2003-10-17
CVE-2003-0659 at NVD
2 known exploits for CVE-2003-0659
Proof-of-concept code and exploit modules indexed by Sploitus