Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2003-0352

89
FAUCET Score

CVE-2003-0352 is a critical buffer overflow vulnerability in a DCOM interface for RPC affecting Microsoft Windows NT 4.0, 2000, XP, and Server 2003. This flaw allows unauthenticated remote attackers to execute arbitrary code with high privileges by sending a specially crafted message. With a CVSS score of 7.5 and a FAUCET Risk Score of 100/100, its severity is high, enabling complete compromise of confidentiality, integrity, and availability. This vulnerability was famously exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms, and exploit code, including Metasploit modules, is publicly available, leading to extensive community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
98.48%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Metasploit: MS03-026 Microsoft RPC DCOM Interface Overflow · Jul 16, 2003
ExploitDB: EDB-16749 · Jan 11, 2011
This CVE's current EPSS score of 0.9848 is in the 100th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

lists.grok.org.uk / pipermail/full-disclosure/2003-July/007079.html
lists.grok.org.uk / pipermail/full-disclosure/2003-July/007357.html
marc.info
marc.info
docs.microsoft.com / en-us/security-updates/securitybulletins/2003/ms03-026
exchange.xforce.ibmcloud.com / vulnerabilities/12629
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A194
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2343
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A296
cert.org / advisories/CA-2003-16.html
US Government Resource
cert.org / advisories/CA-2003-19.html
US Government Resource
kb.cert.org / vuls/id/568148
US Government Resource
securityfocus.com / bid/8205
ExploitPatchVendor Advisory
xfocus.org / documents/200307/2.html