PT-2003-1446 · Microsoft · Windows 2000+3
Brett Moore
·
Published
2003-05-30
·
Updated
2020-11-13
·
CVE-2003-0227
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows Media Services versions prior to the fixed version in Windows NT 4.0 and 2000
Description:
The issue concerns the logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services. It allows remote attackers to cause a denial of service in Internet Information Server (IIS) and potentially execute arbitrary code via a certain network request.
Recommendations:
For Microsoft Windows Media Services in Windows NT 4.0 and 2000, apply the necessary patch or update to fix the issue in the nsiislog.dll ISAPI extension.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Information Server
Windows 2000
Windows Media Services
Windows Nt 4.0