{"api_version":"1","generated_at":"2026-07-23T12:22:00+00:00","cve":"CVE-2003-0910","urls":{"html":"https://cve.report/CVE-2003-0910","api":"https://cve.report/api/cve/CVE-2003-0910.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0910","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0910"},"summary":{"title":"CVE-2003-0910","description":"The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-06-01 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.us-cert.gov/cas/techalerts/TA04-104A.html","name":"http://www.us-cert.gov/cas/techalerts/TA04-104A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA04-104A -- Multiple Vulnerabilities in Microsoft Products","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ciac.org/ciac/bulletins/o-114.shtml","name":"http://www.ciac.org/ciac/bulletins/o-114.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/122076","name":"http://www.kb.cert.org/vuls/id/122076","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#122076","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15707","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15707","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] EEYE: Windows Expand-Down Data Segment Local Privilege Escalation","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS04-011 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A890","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A890","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/10122","name":"http://www.securityfocus.com/bid/10122","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Windows Local Descriptor Table Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.eeye.com/html/Research/Advisories/AD20040413D.html","name":"http://www.eeye.com/html/Research/Advisories/AD20040413D.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"BeyondTrust | Privileged Access Management, Cyber Security, and Remote Access (formerly Bomgar) | BeyondTrust","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A911","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A911","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0910","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0910","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"910","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"910","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_nt","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:12:34.413Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20040413 EEYE: Windows Expand-Down Data Segment Local Privilege Escalation","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html"},{"name":"oval:org.mitre.oval:def:911","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A911"},{"name":"O-114","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/o-114.shtml"},{"name":"oval:org.mitre.oval:def:890","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A890"},{"name":"MS04-011","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011"},{"name":"AD20040413D","tags":["third-party-advisory","x_refsource_EEYE","x_transferred"],"url":"http://www.eeye.com/html/Research/Advisories/AD20040413D.html"},{"name":"TA04-104A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA04-104A.html"},{"name":"10122","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/10122"},{"name":"win-ldt-gain-privileges(15707)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15707"},{"name":"VU#122076","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/122076"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-04-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20040413 EEYE: Windows Expand-Down Data Segment Local Privilege Escalation","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html"},{"name":"oval:org.mitre.oval:def:911","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A911"},{"name":"O-114","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/o-114.shtml"},{"name":"oval:org.mitre.oval:def:890","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A890"},{"name":"MS04-011","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011"},{"name":"AD20040413D","tags":["third-party-advisory","x_refsource_EEYE"],"url":"http://www.eeye.com/html/Research/Advisories/AD20040413D.html"},{"name":"TA04-104A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA04-104A.html"},{"name":"10122","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/10122"},{"name":"win-ldt-gain-privileges(15707)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15707"},{"name":"VU#122076","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/122076"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0910","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20040413 EEYE: Windows Expand-Down Data Segment Local Privilege Escalation","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html"},{"name":"oval:org.mitre.oval:def:911","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A911"},{"name":"O-114","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/o-114.shtml"},{"name":"oval:org.mitre.oval:def:890","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A890"},{"name":"MS04-011","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011"},{"name":"AD20040413D","refsource":"EEYE","url":"http://www.eeye.com/html/Research/Advisories/AD20040413D.html"},{"name":"TA04-104A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA04-104A.html"},{"name":"10122","refsource":"BID","url":"http://www.securityfocus.com/bid/10122"},{"name":"win-ldt-gain-privileges(15707)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15707"},{"name":"VU#122076","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/122076"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0910","datePublished":"2004-04-16T04:00:00.000Z","dateReserved":"2003-11-04T00:00:00.000Z","dateUpdated":"2024-08-08T02:12:34.413Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-06-01 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*","matchCriteriaId":"4E545C63-FE9C-4CA1-AF0F-D999D84D2AFD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*","matchCriteriaId":"E53CDA8E-50A8-4509-B070-CCA5604FFB21"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"910","Ordinal":"1","Title":"CVE-2003-0910","CVE":"CVE-2003-0910","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"910","Ordinal":"1","NoteData":"The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.","Type":"Description","Title":"CVE-2003-0910"},{"CveYear":"2003","CveId":"910","Ordinal":"2","NoteData":"2004-04-16","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"910","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}