CVE-2003-0306

Windows XP - Buffer Overflow via Long .ShellClassInfo Parameter in desktop.ini

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0306. PoCs published by einstein.

AI-analyzed exploit summary This exploit targets CVE-2003-0306, a buffer overflow vulnerability in Windows Shell (desktop.ini parsing). It crafts a malicious desktop.ini file with a long path and shellcode to achieve remote code execution via a crafted URL.

Description

Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by einstein · clocalwindows
https://www.exploit-db.com/exploits/32

This exploit targets CVE-2003-0306, a buffer overflow vulnerability in Windows Shell (desktop.ini parsing). It crafts a malicious desktop.ini file with a long path and shellcode to achieve remote code execution via a crafted URL.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows Shell (Windows XP SP1)
No auth needed
Prerequisites: Access to write files on the target system · Target system running Windows XP SP1
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105284486526310&w=2
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3095
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105301349925036&w=2
Mailing List mailing-list x_refsource_vuln-dev
http://marc.info/?l=vuln-dev&m=105241032526289&w=2

Scores

EPSS 0.0404
EPSS Percentile 89.3%

Details

Status published
Products (1)
microsoft/windows_xp
Published Jun 09, 2003
Tracked Since Feb 18, 2026