Vulnerability record · CVE-2003-0533 · published 1 June 2004
CVE-2003-0533: Microsoft LSASS Active Directory Function Stack Buffer Overflow
Microsoft · Netmeeting
A stack-based buffer overflow exists in Active Directory service functions within LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) on multiple legacy Windows platforms. A remote attacker can send a crafted packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, overflowing the stack. This flaw is notable because it was exploited by the Sasser worm.
Description
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication, has known worm exploitation (Sasser), and affects a wide range of legacy Windows systems, though patching is available.
What it is
A stack-based buffer overflow exists in Active Directory service functions within LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) on multiple legacy Windows platforms. A remote attacker can send a crafted packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, overflowing the stack. This flaw is notable because it was exploited by the Sasser worm.
Impact
Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code with the privileges of the LSASS service, typically SYSTEM. This can lead to full host compromise, worm propagation, and lateral movement.
Attack surface
The vulnerability is reachable over the network via crafted packets processed by LSASS Active Directory service functions. No authentication or user interaction is required, as indicated by the CVSS vector AV:N/AC:L/Au:N.
Exploitation
The description states the flaw was exploited by the Sasser worm, confirming real-world exploitation. It is not listed in CISA KEV, but EPSS is very high at 0.85485 (99.71st percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the Microsoft security update MS04-011 (or the latest available cumulative update for affected platforms) immediately.
- Isolate or decommission unsupported legacy systems (Windows NT 4.0, 2000, XP SP1, Server 2003, 98, ME) that cannot be patched.
- Block or restrict inbound SMB/RPC traffic (TCP 445, 139, 135) at network boundaries to limit exposure of LSASS.
- Enable host-based firewall rules to prevent unauthorized remote access to LSASS-related services.
- Monitor for and remove any unauthorized services or scheduled tasks associated with known worm activity.
Detection
- Monitor for unexpected LSASS crashes or restarts, which may indicate exploitation attempts.
- Inspect DCPROMO.LOG for unusually long or malformed debug entries that could indicate the overflow trigger.
- Use network monitoring to detect anomalous SMB/RPC packets targeting LSASS, especially those resembling Sasser worm traffic.
- Review endpoint logs for processes spawning from LSASS or unusual outbound connections from SYSTEM-level services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0533 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0533), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.