MSRPC DCOM exploit v1.31

Vulnerability exploited: CAN-2003-0352 - BID-8205

Category: Exploits/Remote

This module exploits a buffer overflow and installs a level0 agent into the target host.
This module exploits a buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003.After successful exploitation a level0 agent will be installed.

Supported Systems:
    Windows NT4 Workstation - sp6a (i386)
    Windows NT4 Server - sp6a (i386)
    Windows NT4 Enterprise Server - sp6a (i386)
    Windows 2000 Professional - sp0 (i386)
    Windows 2000 Professional - sp1 (i386)
    Windows 2000 Professional - sp2 (i386)
    Windows 2000 Professional - sp3 (i386)
    Windows 2000 Professional - sp4 (i386)
    Windows 2000 Server - sp0 (i386)
    Windows 2000 Server - sp1 (i386)
    Windows 2000 Server - sp2 (i386)
    Windows 2000 Server - sp3 (i386)
    Windows 2000 Server - sp4 (i386)
    Windows 2000 Advanced Server - sp0 (i386)
    Windows 2000 Advanced Server - sp1 (i386)
    Windows 2000 Advanced Server - sp2 (i386)
    Windows 2000 Advanced Server - sp3 (i386)
    Windows 2000 Advanced Server - sp4 (i386)
    Windows XP Professional - sp0 (i386)
    Windows XP Professional - sp1 (i386)
    Windows XP Home Edition - sp0 (i386)
    Windows XP Home Edition - sp1 (i386)
    Windows 2003 Enterprise Edition - sp0 (i386)
    Windows 2003 Standard Edition - sp0 (i386)


This module is included in the latest version of CORE IMPACT, the first automated comprehensive penetration testing product for accurately identifying information security risks. Click here to learn more about the product.