CVE-2003-0660

Microsoft Windows NT-Server 2003 - RCE

Title source: llm
STIX 2.1

Description

The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.

References (7)

Core 7
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2003-27.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13422
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/838572
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8830
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A198
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A185

Scores

EPSS 0.2304
EPSS Percentile 97.5%

Details

Status published
Products (8)
microsoft/windows_2000 (5 CPE variants)
microsoft/windows_2003_server enterprise
microsoft/windows_2003_server enterprise_64-bit
microsoft/windows_2003_server r2 (2 CPE variants)
microsoft/windows_2003_server standard
microsoft/windows_2003_server web
microsoft/windows_nt 4.0 (31 CPE variants)
microsoft/windows_xp (7 CPE variants)
Published Nov 17, 2003
Tracked Since Feb 18, 2026