Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2003-0660 | First vendor Publication | 2003-11-17 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0660 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:185 | |||
Oval ID: | oval:org.mitre.oval:def:185 | ||
Title: | Automatic ActiveX Approval on WinXP Low Memory | ||
Description: | The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2003-0660 | Version: | 7 |
Platform(s): | Microsoft Windows XP | Product(s): | Authenticode |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:198 | |||
Oval ID: | oval:org.mitre.oval:def:198 | ||
Title: | Automatic ActiveX Approval on Windows 2000 Low Memory | ||
Description: | The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2003-0660 | Version: | 1 |
Platform(s): | Microsoft Windows 2000 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-03-15 | Name : MS04-011 security check File : nvt/remote-MS04-011.nasl |
2005-11-03 | Name : Vulnerability in Authenticode Verification Could Allow Remote Code Execution ... File : nvt/smb_nt_ms03-041.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
11463 | Microsoft Windows Authenticode ActiveX Install Failure Remote Code Execution |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2003-10-15 | Name : Arbitrary code can be executed on the remote host through the web client. File : smb_nt_ms03-041.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:19 |
|
2024-11-28 12:05:41 |
|
2024-08-02 12:02:33 |
|
2024-08-02 01:01:26 |
|
2024-02-02 01:02:19 |
|
2024-02-01 12:01:27 |
|
2023-09-05 12:02:13 |
|
2023-09-05 01:01:19 |
|
2023-09-02 12:02:14 |
|
2023-09-02 01:01:19 |
|
2023-08-12 12:02:44 |
|
2023-08-12 01:01:19 |
|
2023-08-11 12:02:20 |
|
2023-08-11 01:01:20 |
|
2023-08-06 12:02:09 |
|
2023-08-06 01:01:20 |
|
2023-08-04 12:02:13 |
|
2023-08-04 01:01:20 |
|
2023-07-14 12:02:11 |
|
2023-07-14 01:01:20 |
|
2023-03-29 01:02:11 |
|
2023-03-28 12:01:25 |
|
2022-10-11 12:01:56 |
|
2022-10-11 01:01:12 |
|
2021-05-04 12:02:07 |
|
2021-04-22 01:02:13 |
|
2020-05-23 00:15:28 |
|
2019-05-09 12:01:18 |
|
2019-04-30 21:19:17 |
|
2018-10-13 00:22:27 |
|
2017-10-11 09:23:17 |
|
2017-07-19 09:22:22 |
|
2017-07-11 12:01:17 |
|
2016-04-26 12:36:09 |
|
2014-02-17 10:26:27 |
|
2013-05-11 11:52:23 |
|