Vulnerability Description
Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 2000 | All versions |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0015.htmlExploitPatchVendor Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012205.html
- http://marc.info/?l=ntbugtraq&m=106632192709608&w=2
- http://www.cert.org/advisories/CA-2003-27.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/989932PatchThird Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/8833ExploitPatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-04
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13423
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0015.htmlExploitPatchVendor Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012205.html
- http://marc.info/?l=ntbugtraq&m=106632192709608&w=2
- http://www.cert.org/advisories/CA-2003-27.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/989932PatchThird Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/8833ExploitPatchVendor Advisory
FAQ
What is CVE-2003-0662?
CVE-2003-0662 is a vulnerability with a CVSS score of 9.3 (HIGH). Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to ...
How severe is CVE-2003-0662?
CVE-2003-0662 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0662?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 2000.