Vulnerability record · CVE-2003-0109 · published 31 March 2003
CVE-2003-0109: Windows ntdll.dll buffer overflow via WebDAV request
Microsoft · Windows 2000
A buffer overflow in ntdll.dll affects Windows NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP, and can be triggered remotely through a WebDAV request to IIS 5.0. Successful exploitation allows arbitrary code execution in the context of the affected service, making this a serious pre-authentication remote flaw on unpatched systems.
Description
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote code execution with a very high EPSS score and public exploit references, though the affected platforms are legacy and largely retired.
What it is
A buffer overflow in ntdll.dll affects Windows NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP, and can be triggered remotely through a WebDAV request to IIS 5.0. Successful exploitation allows arbitrary code execution in the context of the affected service, making this a serious pre-authentication remote flaw on unpatched systems.
Impact
An unauthenticated remote attacker can execute arbitrary code on the target host, potentially gaining full control of the system. This can lead to data compromise, service disruption, and use of the host as a foothold for further attacks.
Attack surface
The flaw is reachable over the network via a crafted WebDAV request to IIS 5.0, as indicated by the AV:N/AC:L/Au:N vector. No authentication or user interaction is required per the CVSS vector and description.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.85681 (99.7th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware group usage is documented in the record.
What to do
- Apply the Microsoft security update for MS03-007 (Q815021) to affected Windows NT 4.0, Windows 2000, and Windows XP systems.
- Disable or restrict WebDAV on IIS 5.0 where it is not required.
- Block or filter WebDAV methods (for example PROPFIND, PROPPATCH, MKCOL, COPY, MOVE) at the perimeter or IIS level if WebDAV is not needed.
- Isolate or retire unsupported Windows NT 4.0 and Windows 2000 hosts that cannot be patched.
- Monitor IIS logs for anomalous WebDAV requests and unexpected process behavior on web servers.
Detection
- Review IIS 5.0 logs for unusual or malformed WebDAV requests, especially PROPFIND and related methods with oversized or non-standard headers.
- Monitor for unexpected child processes or command execution spawned by IIS worker processes (inetinfo.exe, dllhost.exe).
- Use host-based detection for crashes or memory corruption in ntdll.dll or IIS-related processes.
- Check for the presence of MS03-007/Q815021 patch level on Windows NT 4.0, Windows 2000, and Windows XP systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0109 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0109), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.