MS03-018: Cumulative Patch for Internet Information Services (11114)

Critical Nessus Plugin ID 11683


Arbitrary code can be executed on the remote web server.


The remote host is running a version of IIS that contains various flaws that could allow remote attackers to disable this service remotely and local attackers (or remote attackers with the ability to upload arbitrary files on this server) to gain SYSTEM level access on this host.


Microsoft has released a set of patches for IIS 4.0, 5.0 and 5.1.

See Also

Plugin Details

Severity: Critical

ID: 11683

File Name: smb_nt_ms03-018.nasl

Version: $Revision: 1.40 $

Type: local

Agent: windows

Published: 2003/06/02

Modified: 2017/05/25

Dependencies: 13855, 57033

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:H/RL:OF/RC:C


Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: No exploit is required

Patch Publication Date: 2003/05/28

Vulnerability Publication Date: 2003/04/18

Reference Information

CVE: CVE-2003-0223, CVE-2003-0224, CVE-2003-0225, CVE-2003-0226

BID: 7731, 7733, 7734, 7735

OSVDB: 13385, 4655, 4863, 7737

MSFT: MS03-018

MSKB: 811114