← Vulnerability feed

Vulnerability record · CVE-2003-1141 · published 4 November 2003

CVE-2003-1141: NIPrint LPD/LPR print server buffer overflow via TCP port 515

Network Instruments · Niprint Lpd Lpr Print Server

NIPrint 4.10 contains a buffer overflow that can be triggered by sending a long string to TCP port 515, the LPD/LPR print service port. A remote, unauthenticated attacker can overflow the buffer and potentially execute arbitrary code on the host. The flaw is in an obsolete print server, but the exposed service and public exploit references make it a real risk where the product is still deployed.

7.5 CVSS 2.0 High EPSS 68% · top 0.7%
7.5CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution with public exploit references and very high EPSS, though the product is legacy and not in KEV.

What it is

NIPrint 4.10 contains a buffer overflow that can be triggered by sending a long string to TCP port 515, the LPD/LPR print service port. A remote, unauthenticated attacker can overflow the buffer and potentially execute arbitrary code on the host. The flaw is in an obsolete print server, but the exposed service and public exploit references make it a real risk where the product is still deployed.

Impact

Successful exploitation allows a remote attacker to execute arbitrary code with the privileges of the NIPrint service, giving full control of the affected host. Even without code execution, the overflow can crash the print service, disrupting printing.

Attack surface

The flaw is reached over the network through TCP port 515, the LPD/LPR protocol port, with no authentication required per the CVSS vector (AV:N/AC:L/Au:N). No user interaction is indicated; the attacker only needs network access to the port.

Exploitation

CVE-2003-1141 is not listed in CISA KEV, but EPSS is high at roughly 0.68 probability (99th percentile), and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.

What to do

  • Patch or upgrade NIPrint to a fixed release if the vendor provides one; if no fix exists, retire or replace the product.
  • Block or restrict TCP port 515 to trusted print clients only, and never expose it to the internet.
  • Segment print servers on a dedicated VLAN with strict firewall rules limiting inbound access.
  • Run the NIPrint service with least privilege and isolate it from sensitive systems.
  • Monitor vendor and CVE feeds for updated guidance, since the record is old and may lack a current patch path.

Detection

  • Monitor network traffic to TCP port 515 for unusually long or malformed LPD/LPR commands.
  • Alert on crashes or restarts of the NIPrint service, which may indicate exploitation attempts.
  • Use IDS/IPS signatures for LPD buffer overflow patterns targeting port 515.
  • Audit exposed hosts for NIPrint 4.10 or other legacy LPD services reachable from untrusted networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-1141 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2003-1141), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.