Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
Loading...
Loading...
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
March 31, 2003
April 16, 2026
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (1 Metasploit module) (9 Exploit-DB entries). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Microsoft IIS 5.0 - WebDAV 'ntdll.dll' Path Overflow (MS03-007) (Metasploit)
Open source ↗Microsoft IIS 5.0 - WebDAV Remote Code Execution (3) (xwdav)
Open source ↗Microsoft Windows - WebDAV Remote Code Execution (2)
Open source ↗MS03-007 Microsoft IIS 5.0 WebDAV ntdll.dll Path Overflow
Open source ↗Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (3)
Open source ↗Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (2)
Open source ↗Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (1)
Open source ↗Microsoft IIS 5.0 - WebDAV Remote
Open source ↗Microsoft IIS - WebDAV 'ntdll.dll' Remote Overflow
Open source ↗Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (4)
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2003-0109
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.