CVE Database
/

CVE-2003-0533

Back to search

CVE-2003-0533

Published: Apr 16, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.

VendorProductVersions

n/a

n/a

affected
n/a

References

O-114
third-party-advisory
government-resource
x_refsource_CIAC
AD20040413C
third-party-advisory
x_refsource_EEYE
win-lsass-bo(15699)
vdb-entry
x_refsource_XF
oval:org.mitre.oval:def:919
vdb-entry
signature
x_refsource_OVAL
MS04-011
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:898
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:883
vdb-entry
signature
x_refsource_OVAL
TA04-104A
third-party-advisory
x_refsource_CERT
10108
vdb-entry
x_refsource_BID
VU#753212
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now