7.5
CVSSv2

CVE-2003-0818

Published: 03/03/2004 Updated: 30/04/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote malicious users to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 2000

microsoft windows 2003 server web

microsoft windows nt 4.0

microsoft windows xp

microsoft windows 2003 server enterprise_64-bit

microsoft windows 2003 server r2

microsoft windows 2003 server enterprise

microsoft windows 2003 server standard

Exploits

/* * MS04-007 Exploit LSASSEXE Win2k Pro Remote Denial-of-Service * * Copyright (C) 2004 Christophe Devine * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation; either version 2 of the License, or * (at your opti ...
# Microsoft ASN1 remote exploit for CVE-2005-1935 // MS04-007 # Solar Eclipse # solareclipse at phreedom dot org githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/3022targz (12262006-killbilltargz) # milw0rmcom [2004-03-26] ...
## # $Id: ms04_007_killbillrb 9929 2010-07-25 21:37:54Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' clas ...