Description
The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.
References (7)
Core 7
Core References
US Government Resource third-party-advisory
x_refsource_cert
http://www.cert.org/advisories/CA-2003-27.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13422
Patch, Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/838572
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/8830
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-041
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A198
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A185
Scores
EPSS
0.2304
EPSS Percentile
97.5%
Details
Status
published
Products (8)
microsoft/windows_2000
(5 CPE variants)
microsoft/windows_2003_server
enterprise
microsoft/windows_2003_server
enterprise_64-bit
microsoft/windows_2003_server
r2 (2 CPE variants)
microsoft/windows_2003_server
standard
microsoft/windows_2003_server
web
microsoft/windows_nt
4.0 (31 CPE variants)
microsoft/windows_xp
(7 CPE variants)
Published
Nov 17, 2003
Tracked Since
Feb 18, 2026