Overview
The Microsoft ASN.1 Library improperly decodes malformed ASN.1 length values which could allow an unauthenticated, remote attacker to execute arbitrary code with SYSTEM privileges.
Description
| Abstract Syntax Notation number One (ASN.1) is an international standard used to describe and transmit data packets between applications and across networks. There is a buffer overflow vulnerability in the Microsoft ASN.1 Library that could allow an unauthenticated, remote attacker to execute arbitrary code with SYSTEM privileges on the affected system. | 
Impact
| An unauthenticated, remote attacker could execute arbitrary code with SYSTEM privileges. | 
Solution
| Apply Patch Apply the patch (828028) referenced in Microsoft Security Bulletin MS04-007. | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
This vulnerability was reported by eEye Digital Security.
This document was written by Damon Morda.
Other Information
| CVE IDs: | CVE-2003-0818 | 
| Severity Metric: | 27.72 | 
| Date Public: | 2004-02-10 | 
| Date First Published: | 2004-02-10 | 
| Date Last Updated: | 2004-02-11 15:38 UTC | 
| Document Revision: | 20 |