Vulnerability record · CVE-2003-0349 · published 24 July 2003
CVE-2003-0349: Windows Media Services ISAPI logging DLL buffer overflow
Microsoft · Windows 2000
The nsiislog.dll ISAPI extension used by Microsoft Windows Media Services on IIS 5.0 contains a buffer overflow in its multicast request logging component. A remote attacker can trigger it with a large POST request, and the flaw allows arbitrary code execution on the server.
Description
Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote code execution with a very high EPSS score and public exploit references, even though it is not in KEV.
What it is
The nsiislog.dll ISAPI extension used by Microsoft Windows Media Services on IIS 5.0 contains a buffer overflow in its multicast request logging component. A remote attacker can trigger it with a large POST request, and the flaw allows arbitrary code execution on the server.
Impact
An unauthenticated remote attacker can execute arbitrary code in the context of the IIS/Media Services process, potentially taking full control of the host.
Attack surface
Reachable over the network via HTTP POST requests to nsiislog.dll on an IIS 5.0 server running Windows Media Services; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.803, 99.6th percentile) and a reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply Microsoft security bulletin MS03-022 or the vendor patch for nsiislog.dll immediately.
- Remove or disable the nsiislog.dll ISAPI extension if Media Services logging is not required.
- Restrict external HTTP access to the affected IIS/Media Services host via firewall or reverse proxy rules.
- Upgrade or retire Windows 2000/IIS 5.0 systems that cannot be patched, since the platform is end-of-life.
Detection
- Inspect IIS and HTTP logs for large POST requests targeting nsiislog.dll.
- Alert on unexpected w3wp/inetinfo child processes or command shells spawned by IIS.
- Monitor for file writes or new executables in web-accessible directories following nsiislog.dll requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0349 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0349), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.