CVE-2003-0117: Buffer Overflow
Published May 2, 2003
·Updated
Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.
Affected Software
2 affected components
Microsoft BizTalk Server=2002
Microsoft BizTalk Server=2002
Event History
May 2, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
May 12, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0117?
CVE-2003-0117 is rated as critical due to the potential for attackers to execute arbitrary code remotely.
2
How do I fix CVE-2003-0117?
To fix CVE-2003-0117, apply the security patch provided by Microsoft for BizTalk Server 2002.
3
What versions of Microsoft BizTalk Server are affected by CVE-2003-0117?
CVE-2003-0117 affects Microsoft BizTalk Server 2002, including both Developer and Enterprise editions.
4
What type of vulnerability is CVE-2003-0117?
CVE-2003-0117 is a buffer overflow vulnerability in the HTTP receiver function of BizTalk Server.
5
Can CVE-2003-0117 be exploited without authentication?
Yes, CVE-2003-0117 can be exploited by unauthenticated attackers who send crafted requests to the HTTP receiver.