CVE-2003-0818: Integer Overflow
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0818?
CVE-2003-0818 is classified as a critical vulnerability that allows remote code execution.
How do I fix CVE-2003-0818?
To fix CVE-2003-0818, apply the latest security updates and patches provided by Microsoft for affected Windows versions.
Which Microsoft products are affected by CVE-2003-0818?
CVE-2003-0818 affects Microsoft Windows NT 4.0, Windows 2000, and Windows XP among other associated libraries.
Can CVE-2003-0818 be exploited remotely?
Yes, CVE-2003-0818 can be exploited remotely by attackers through specially crafted ASN.1 BER encodings.
Is there a workaround for CVE-2003-0818?
While the best solution is to apply updates, disabling or restricting services that utilize the affected libraries may serve as a temporary workaround.