A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2003-11-17 05:00
Updated : 2024-02-15 21:19
NVD link : CVE-2003-0813
Mitre link : CVE-2003-0813
CVE.ORG link : CVE-2003-0813
JSON object : View
Products Affected
microsoft
- windows_server_2003
- windows_nt
- windows_98
- windows_2000
- windows_xp
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition