← Vulnerability feed

Vulnerability record · CVE-2003-0719 · published 1 June 2004

CVE-2003-0719: Microsoft SSL PCT handshake buffer overflow allows remote code execution

Microsoft · Netmeeting

The Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library contains a buffer overflow reachable via PCT 1.0 handshake packets. It affects Windows NT 4.0 SP6a, 2000 SP2-SP4, XP SP1, Server 2003, NetMeeting, Windows 98 and Windows ME. Because the flaw sits in a network-facing TLS/SSL component, it matters for any host still exposing those legacy stacks.

7.5 CVSS 2.0 High EPSS 81% · top 0.4%
7.5CVSS 2.0 base score
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated buffer overflow with high EPSS despite no KEV listing, though the affected platforms are largely legacy.

What it is

The Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library contains a buffer overflow reachable via PCT 1.0 handshake packets. It affects Windows NT 4.0 SP6a, 2000 SP2-SP4, XP SP1, Server 2003, NetMeeting, Windows 98 and Windows ME. Because the flaw sits in a network-facing TLS/SSL component, it matters for any host still exposing those legacy stacks.

Impact

A remote attacker can execute arbitrary code in the context of the affected service, potentially gaining full control of the host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.

Attack surface

Reached over the network by sending crafted PCT 1.0 handshake packets to a service using the Microsoft SSL library; the vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.812 probability, 99.6th percentile), indicating strong predicted exploitation likelihood. Reference tags are patch and advisory only, so no public exploit code is confirmed by this record.

What to do

  • Apply the Microsoft security bulletin MS04-011 patch for all affected platforms.
  • Disable PCT support in the SSL/TLS configuration where the platform allows it, since PCT is a legacy protocol.
  • Block or filter PCT 1.0 handshake traffic at network boundaries and restrict exposed SSL services to trusted networks.
  • Retire or isolate unsupported end-of-life systems (NT 4.0, 98, ME, 2000, XP SP1) that cannot be patched.
  • Verify patch state with the OVAL definitions referenced for this CVE.

Detection

  • Monitor network traffic for PCT 1.0 handshake packets or anomalous SSL handshake sequences to exposed services.
  • Alert on crashes or unexpected restarts of SSL/TLS-serving processes on affected hosts.
  • Use the OVAL definitions (def:1093, 889, 903, 951) to scan for unpatched systems.
  • Review host logs for suspicious process creation or outbound connections originating from SSL service accounts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.kb.cert.org/vuls/id/586540 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/archive/1/361836 PatchVendor Advisory
http://www.us-cert.gov/cas/techalerts/TA04-104A.html Third Party AdvisoryUS Government Resource
http://xforce.iss.net/xforce/alerts/id/168 PatchVendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1093
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A889
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A903
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A951
http://www.kb.cert.org/vuls/id/586540 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/archive/1/361836 PatchVendor Advisory
http://www.us-cert.gov/cas/techalerts/TA04-104A.html Third Party AdvisoryUS Government Resource
http://xforce.iss.net/xforce/alerts/id/168 PatchVendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1093
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A889
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A903
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A951

Track CVE-2003-0719 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed7.8CVE-2015-1701Microsoft Windows Win32k.sys Local Privilege EscalationWin32k.sys in the Windows kernel-mode drivers fails to properly validate input, allowing a local user to elevate privileges by running a crafted appl…KEVEPSS 56%analysed7.8CVE-2013-5065Microsoft Windows NDProxy.sys kernel local privilege escalationNDProxy.sys in the Windows kernel on Windows XP SP2/SP3 and Server 2003 SP2 fails to properly validate input, letting a local user escalate privilege…KEVEPSS 35%analysed7.8CVE-2010-0232Windows kernel exception handler privilege escalation via NTVDMThe Windows kernel fails to properly validate certain BIOS calls when 16-bit application support is enabled on 32-bit x86 systems. A local user can c…KEVEPSS 29%analysed7.8CVE-2009-1123Microsoft Windows kernel improper validation allows local privilege escalationThe Windows kernel fails to properly validate changes to unspecified kernel objects, letting a local user elevate privileges through a crafted applic…KEVEPSS 4.9%analysed7.8CVE-2004-0210Microsoft Windows POSIX component buffer overflow allows local code executionThe POSIX subsystem in Windows NT and Windows 2000 contains a classic buffer overflow (CWE-120) that can be triggered by local users through crafted …KEVEPSS 7.2%analysed

Source: NIST National Vulnerability Database (record CVE-2003-0719), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.