CVE-2003-0346

Microsoft Windows DirectX MIDI - RCE

Title source: llm
STIX 2.1

Description

Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A218
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/561284
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2003-18.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1104
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/265232
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1095
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105899759824008&w=2

Scores

EPSS 0.3267
EPSS Percentile 98.2%

Details

Status published
Products (6)
microsoft/directx 5.2
microsoft/directx 6.1
microsoft/directx 7.0
microsoft/directx 7.0a
microsoft/directx 8.1
microsoft/directx 9.0a
Published Aug 27, 2003
Tracked Since Feb 18, 2026