CVE-2003-0818
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
- Affected products
- Asn.1 Library, Windows 2000, Windows Nt 4.0, Windows Xp
- Microsoft Windows 2000
- All versions
- Microsoft Windows 2003 Server
- = enterprise, enterprise_64-bit, R2, standard, web
- Microsoft Windows Nt
- = 4.0
- Microsoft Windows Xp
- All versions
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 82.2% (100th percentile)
- NVD status
- Modified
- Published
- 2004-02-11
CVE-2003-0818 at NVD
6 known exploits for CVE-2003-0818
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft Windows - ASN.1 Library Bitstring Heap Overflow (MS04-007) (Metasploit)
Microsoft ASN.1 Library Bitstring Heap Overflow
MS04-007 Microsoft ASN.1 Library Bitstring Heap Overflow
Microsoft Windows - ASN.1 Remote (MS04-007)
Immunity Canvas: MS04_007
Microsoft Windows - ASN.1 'LSASS.exe' Remote Denial of Service (MS04-007)