Vulnerability record · CVE-2003-1339 · published 31 December 2003
CVE-2003-1339: eZnet.exe stack buffer overflow in eZ collaboration products
Ezmeeting · Ezmeeting
eZnet.exe, shipped with eZphotoshare, eZmeeting, eZnetwork and eZshare, contains a stack-based buffer overflow reachable over the network. Long GET requests or long operation/autologin parameters to SwEzModule.dll can crash the service or allow arbitrary code execution. The flaw is remotely exploitable without authentication, making it a serious pre-auth risk for any exposed instance.
Description
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote attackers to cause a denial of service (crash) or execute arbitrary code, as demonstrated via (1) a long GET request and (2) a long operation or autologin parameter to SwEzModule.dll.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, public exploit code, and a very high EPSS percentile make this an urgent exposure if the service is still reachable.
What it is
eZnet.exe, shipped with eZphotoshare, eZmeeting, eZnetwork and eZshare, contains a stack-based buffer overflow reachable over the network. Long GET requests or long operation/autologin parameters to SwEzModule.dll can crash the service or allow arbitrary code execution. The flaw is remotely exploitable without authentication, making it a serious pre-auth risk for any exposed instance.
Impact
An unauthenticated remote attacker can crash the service (denial of service) or, with a crafted payload, execute arbitrary code in the context of the eZnet.exe process. That yields full compromise of confidentiality, integrity and availability on the host.
Attack surface
Reached over the network via HTTP requests to eZnet.exe and SwEzModule.dll, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required; the attacker only needs network access to the listening service.
Exploitation
Not listed in CISA KEV, but EPSS is 0.486 (98.8th percentile) and a public Exploit-DB entry (133) plus an Exploit-tagged SecurityTracker reference exist, indicating public exploit code is available.
What to do
- Apply the vendor patch or upgrade to a fixed eZnet.exe/SwEzModule.dll build; if no patch exists, retire or replace the affected product.
- Remove internet exposure of eZnet.exe and SwEzModule.dll; restrict access to trusted networks via firewall or reverse proxy.
- Enforce strict input length validation and reject oversized GET requests and operation/autologin parameters at the web tier.
- Run the service under a low-privilege account and enable OS-level exploit mitigations (DEP, ASLR, stack cookies) where supported.
- Monitor vendor and CVE feeds for updated guidance since the record is old and may lack current patch information.
Detection
- Inspect web/proxy logs for unusually long GET request lines or oversized operation and autologin parameters targeting SwEzModule.dll.
- Alert on eZnet.exe process crashes or restarts, which may indicate exploitation attempts.
- Deploy network IDS signatures for known Exploit-DB 133 patterns against eZnet.exe and SwEzModule.dll.
- Monitor for unexpected child processes or outbound connections spawned by eZnet.exe as a sign of code execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-1339 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-1339), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.