Back

CVE-2003-0813

A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.

Published: Nov 17, 2003 Modified: Jun 16, 2026
CWE-367

CVSS Metrics

Affected Products (10)

Vendor Product Version
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_98 -
microsoft windows_nt 4.0
microsoft windows_nt 4.0
microsoft windows_server_2003 *
microsoft windows_server_2003 *
microsoft windows_xp -
microsoft windows_xp -

GitHub Security Advisory GHSA-5f25-6f2x-h9x6

A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch...

Risk Scores

CVSS Score 5.1 / 10
EPSS Score 15.30%

Top 4% most likely to be exploited

Threat Score 25 / 100

Data Sources

NVD EPSS GitHub