Microsoft SSL PCT Buffer Overflow Vulnerability

  Severity: HIGH
  CVE Identifier: CVE-2003-0719
  Advisory Date: JUL 21, 2015

  DESCRIPTION

Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1000584
  Trend Micro Deep Security DPI Rule Name: 1000584 - Microsoft SSL PCT Buffer Overflow Vulnerability

  AFFECTED SOFTWARE AND VERSION

  • Microsoft NetMeeting
  • Microsoft Windows 2000 SP2
  • Microsoft Windows 2000 SP4
  • Microsoft Windows 98
  • Microsoft Windows ME
  • Microsoft Windows NT 4.0 SP6a
  • Microsoft Windows Server 2003
  • Microsoft Windows XP SP1