CVE-2003-0717
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
- Affected products
- Msn Messenger Service, Windows Nt, Windows Server 2003
- Microsoft Windows 2000
- All versions
- Microsoft Windows 2003 Server
- = enterprise, enterprise_64-bit, R2, standard, web
- Microsoft Windows Me
- All versions
- Microsoft Windows Nt
- = 4.0
- Microsoft Windows Xp
- All versions
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 61.0% (99th percentile)
- NVD status
- Modified
- Published
- 2003-10-17
CVE-2003-0717 at NVD
5 known exploits for CVE-2003-0717
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft Messenger (Linux) - Denial of Service (MS03-043)
MS Messenger Denial of Service Exploit (MS03-043) (linux ver)
Microsoft Windows Messenger Service (French) - Remote (MS03-043)
Microsoft Windows XP/2000 - Messenger Service Buffer Overrun (MS03-043)
Microsoft Windows Messenger Service - Denial of Service (MS03-043)