← Vulnerability feed

Vulnerability record · CVE-2003-0110 · published 5 May 2003

CVE-2003-0110: Microsoft isa server vulnerability

Microsoft · Isa Server

The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.

5.0 CVSS 2.0 Medium EPSS 18% · top 2.9%
5.0CVSS 2.0 base score
18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-0110 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-7027Microsoft isa server vulnerabilityMicrosoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remo…EPSS 15%10.0CVE-2003-0819Microsoft proxy server memory buffer overflow vulnerabilityBuffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in …EPSS 41%9.3CVE-2009-0562Microsoft isa server vulnerabilityThe Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, …EPSS 26%9.3CVE-2009-1534Microsoft Office Web Components ActiveX control buffer overflowThe Office Web Components ActiveX control contains a buffer overflow that is triggered by crafted property values. Because the control is loaded in t…EPSS 52%analysed9.3CVE-2009-1136Microsoft Office Web Components ActiveX control remote code executionThe Microsoft Office Web Components Spreadsheet ActiveX control (OWC10/OWC11) can be abused through a crafted call to the msDataSourceObject method w…EPSS 62%analysed9.0CVE-2009-1135Microsoft isa server permissions and access controls vulnerabilityMicrosoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, w…EPSS 26%7.5CVE-2006-3652Microsoft isa server vulnerabilityMicrosoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing…EPSS 19%7.5CVE-2006-1651Microsoft isa server vulnerabilityMicrosoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE:…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2003-0110), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.