Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2003-0533
Description:Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2003-0533
BugTraq ID: 10108
http://www.securityfocus.com/bid/10108
Bugtraq: 20040429 MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC) (Google Search)
http://marc.info/?l=bugtraq&m=108325860431471&w=2
Cert/CC Advisory: TA04-104A
http://www.us-cert.gov/cas/techalerts/TA04-104A.html
CERT/CC vulnerability note: VU#753212
http://www.kb.cert.org/vuls/id/753212
Computer Incident Advisory Center Bulletin: O-114
http://www.ciac.org/ciac/bulletins/o-114.shtml
eEye Security Advisory: AD20040413C
http://www.eeye.com/html/Research/Advisories/AD20040413C.html
http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020069.html
Microsoft Security Bulletin: MS04-011
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A883
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A898
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A919
XForce ISS Database: win-lsass-bo(15699)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15699




© 1998-2025 E-Soft Inc. All rights reserved.