Remote Code Execution Vulnerability in Windows RPC Services
CVE-2002-1561

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
2 April 2003

Summary

The RPC component in Microsoft Windows 2000, NT 4.0, and XP is susceptible to a denial of service attack. Attackers can exploit this vulnerability by sending a specially crafted malformed packet to the RPC Endpoint Mapper on TCP port 135. This results in a null pointer dereference within the service, causing it to become unresponsive and effectively disabling the RPC service, which is critical for various network functions.

References

EPSS Score

58% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.