CVE-2003-0349

Microsoft Windows Media Services <5.0 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2003-0349. PoCs published by Metasploit, firew0rker, hdm, including Metasploit module exploits/windows/isapi/ms03_022_nsiislog_post.

AI-analyzed exploit summary This is a Metasploit module exploiting a buffer overflow in the nsiislog.dll ISAPI filter (CVE-2003-0349) via a maliciously crafted POST request. It targets Windows 2000 and XP systems, bypassing the MS03-019 patch, and achieves remote code execution.

Description

Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16355

This is a Metasploit module exploiting a buffer overflow in the nsiislog.dll ISAPI filter (CVE-2003-0349) via a maliciously crafted POST request. It targets Windows 2000 and XP systems, bypassing the MS03-019 patch, and achieves remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft IIS with nsiislog.dll (Windows Media Server)
No auth needed
Prerequisites: Network access to vulnerable IIS server · nsiislog.dll accessible at the specified path
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by firew0rker · cremotewindows
https://www.exploit-db.com/exploits/48

This exploit targets CVE-2003-0349, a buffer overflow in Windows Media Services (nsiislog.dll) to achieve remote command execution. It crafts a malicious HTTP POST request with shellcode to bind a shell on port 34816.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Windows Media Services (nsiislog.dll version 4.1.0.3917)
No auth needed
Prerequisites: Network access to target · Windows Media Services running on target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by firew0rker · cremotewindows
https://www.exploit-db.com/exploits/22837

This exploit targets a buffer overflow vulnerability in Windows Media Services (CVE-2003-0349) via the nsiislog.dll ISAPI extension. It crafts a malicious HTTP POST request to execute arbitrary shellcode, binding a shell to port 34816.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Windows Media Services (nsiislog.dll version 4.1.0.3917)
No auth needed
Prerequisites: Network access to the target server · Windows Media Services with vulnerable nsiislog.dll
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
by hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/isapi/ms03_022_nsiislog_post.rb

This Metasploit module exploits a buffer overflow in the nsiislog.dll ISAPI filter (CVE-2003-0349) by sending a maliciously crafted POST request to trigger an SEH overwrite, leading to remote code execution on vulnerable Microsoft IIS servers.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft IIS with nsiislog.dll (Windows 2000/XP)
No auth needed
Prerequisites: Vulnerable IIS server with nsiislog.dll exposed · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105665030925504&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/9115
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/113716
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A938
Exploit, Patch, Vendor Advisory mailing-list x_refsource_ntbugtraq
http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0306&L=NTBUGTRAQ&P=R4563
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1007059

Scores

EPSS 0.8027
EPSS Percentile 99.6%

Details

Status published
Products (1)
microsoft/windows_2000
Published Jul 24, 2003
Tracked Since Feb 18, 2026