A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.
结论预警: CVE-2003-0813 综合评估为中等风险(53.6/100):CVSS 技术影响为中级,利用概率偏高(EPSS 14.84%,百分位 96%) 核心证据: EPSS 显示该漏洞近期被利用的可能性处于高位。 强制指令: 被利用概率偏高—请排查暴露面并优先安排修补。
风险随态势动态变化;本站持续评估并同步更新本页展示内容。
EPSS 日更估计相对被利用可能性;百分位表示该 CVE 在已评分漏洞中的相对排名(越高表示相对更严重)。
| # | 日期 | 旧 EPSS 分数 | 新 EPSS 分数 | 变化(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-06-20 | 15.30% | 14.84% | -0.46% |
| 2 | 2026-06-19 | 14.84% | 15.30% | +0.46% |
| 3 | 2026-06-15 | — | 14.84% | — |
完整 EPSS 历史 (共 29 条)
该 CVE 的 CVSS 指标。
| 底座分 | 版本 | 严重度 | 向量 | 可利用性 | 影响 | 分数来源 |
|---|---|---|---|---|---|---|
| 5.1 | 2.0 | MEDIUM |
|
4.9 | 6.4 | [email protected] |
| 厂商 | 产品 | 版本 | 原始 CPE |
|---|---|---|---|
| microsoft | windows_2000 | — | cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:* |
| microsoft | windows_2000 | — | cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:* |
| microsoft | windows_2000 | — | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* |
| microsoft | windows_98 | — | cpe:2.3:o:microsoft:windows_98:-:*:*:*:*:*:*:* |
| microsoft | windows_nt | 4.0 | cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:*:*:server:*:*:* |
| microsoft | windows_nt | 4.0 | cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:*:*:terminal_server:*:*:* |
| microsoft | windows_server_2003 | — | cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:x64:* |
| microsoft | windows_server_2003 | — | cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:x86:* |
| microsoft | windows_xp | — | cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:* |
| microsoft | windows_xp | — | cpe:2.3:o:microsoft:windows_xp:-:sp1:*:*:*:*:*:* |