Vulnerability record · CVE-2003-0719 · published 1 June 2004
CVE-2003-0719: Microsoft SSL PCT handshake buffer overflow allows remote code execution
Microsoft · Netmeeting
The Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library contains a buffer overflow reachable via PCT 1.0 handshake packets. It affects Windows NT 4.0 SP6a, 2000 SP2-SP4, XP SP1, Server 2003, NetMeeting, Windows 98 and Windows ME. Because the flaw sits in a network-facing TLS/SSL component, it matters for any host still exposing those legacy stacks.
Description
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable, unauthenticated buffer overflow with high EPSS despite no KEV listing, though the affected platforms are largely legacy.
What it is
The Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library contains a buffer overflow reachable via PCT 1.0 handshake packets. It affects Windows NT 4.0 SP6a, 2000 SP2-SP4, XP SP1, Server 2003, NetMeeting, Windows 98 and Windows ME. Because the flaw sits in a network-facing TLS/SSL component, it matters for any host still exposing those legacy stacks.
Impact
A remote attacker can execute arbitrary code in the context of the affected service, potentially gaining full control of the host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reached over the network by sending crafted PCT 1.0 handshake packets to a service using the Microsoft SSL library; the vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.812 probability, 99.6th percentile), indicating strong predicted exploitation likelihood. Reference tags are patch and advisory only, so no public exploit code is confirmed by this record.
What to do
- Apply the Microsoft security bulletin MS04-011 patch for all affected platforms.
- Disable PCT support in the SSL/TLS configuration where the platform allows it, since PCT is a legacy protocol.
- Block or filter PCT 1.0 handshake traffic at network boundaries and restrict exposed SSL services to trusted networks.
- Retire or isolate unsupported end-of-life systems (NT 4.0, 98, ME, 2000, XP SP1) that cannot be patched.
- Verify patch state with the OVAL definitions referenced for this CVE.
Detection
- Monitor network traffic for PCT 1.0 handshake packets or anomalous SSL handshake sequences to exposed services.
- Alert on crashes or unexpected restarts of SSL/TLS-serving processes on affected hosts.
- Use the OVAL definitions (def:1093, 889, 903, 951) to scan for unpatched systems.
- Review host logs for suspicious process creation or outbound connections originating from SSL service accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0719 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0719), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.