Launch Printer Friendly Page Security TechCenter > Security Bulletins > Microsoft Security Bulletin MS03-007

Microsoft Security Bulletin MS03-007

Unchecked Buffer In Windows Component Could Cause Server Compromise (815021)

Originally posted: March 17, 2003
Updated: May 30, 2003

Summary

Who should read this bulletin: 
Systems administrators running Microsoft ® Windows ® NT 4.0, Windows 2000, and Windows XP.

Impact of vulnerability: 
Run code of attacker's choice

Maximum Severity Rating: 
Critical

Recommendation: 
Systems administrators should apply the patch immediately

End User Bulletin:
An end user version of this bulletin is available at: http://www.microsoft.com/athome/security/update/bulletins/default.mspx

Affected Software:

  • Microsoft Windows NT 4.0
  • Microsoft Windows NT 4.0 Terminal Server Edition
  • Microsoft Windows 2000
  • Microsoft Windows XP

Not Affected Software:

  • Microsoft Windows Server 2003

General Information

Technical details

Frequently asked questions

Patch availability

Other information:

Acknowledgments

Microsoft thanks nesumin from :: Operash :: for reporting the Windows XP vulnerability to us and working with us to protect customers.

Support:

Security Resources: The Microsoft TechNet Security Web Site provides additional information about security in Microsoft products.

Disclaimer:

The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions:

  • V1.0 (March 17, 2003): Bulletin Created.
  • V1.1 (March 18, 2003): Added new information in the Caveats under in the Additional Information section, clarified affected Windows component throughout the bulletin, added a question regarding IIS 5.0 to the Frequently Asked Questions section, added a question regarding changes to the Caveats in the Additional Information section to the Frequently Asked Questions section.
  • V2.0 (April 23, 2003): Updated to include details of NT 4.0 patch.
  • V2.1 (April 24, 2003): Updated to include download link for NT4 package for Japanese NEC
  • V2.2 (April 24, 2003): Provided additional clarification in FAQ regarding supercedence of Windows 2000 patch by the patch in MS03-013.
  • V3.0 (May 28, 2003): Updated to include details of Windows XP patch.
  • V3.1 (May 28, 2003): Updated to include correct Windows NT 4.0 and Windows XP verification keys.
  • V3.2 (May 28, 2003): Updated frequently asked questions section regarding IIS 5.1
  • V3.3 (May 30, 2003): Updated acknowledgments section.
  • V3.4 (September 18, 2003): Updated to include Windows XP SP1 verification keys.