Microsoft disclosed critical vulnerabilities in the Windows RPCSS service used for DCOM activation, including buffer overruns that let remote attackers send malformed RPC messages and execute arbitrary code with Local System privileges. The flaws affected Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, and Microsoft said the updated fix in MS03-039 superseded earlier patches from MS03-026 and MS01-048 while also addressing a denial-of-service issue in the same component.
Security researchers and network defenders reported that the DCOM-related RPC weakness, primarily exposed over TCP/UDP 135, was already being scanned and exploited in the wild, with underground exploit code in circulation and additional concern around TCP 593 and COM Internet Services exposure. Microsoft and ISS urged organizations to deploy the patch immediately and reduce exposure by filtering affected RPC/DCOM ports, disabling COM Internet Services and RPC over HTTP where possible, using host firewalls or IPsec filters, and disabling DCOM on systems that did not require it.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft published Security Bulletin MS03-039 disclosing three vulnerabilities in the Windows RPCSS component that handles DCOM activation, including two critical buffer overruns enabling remote code execution and one denial-of-service flaw. The bulletin rated the issue Critical for affected Windows versions, said the update superseded MS03-026 and MS01-048, and recommended immediate deployment.
Internet Security Systems reported a buffer overflow in the Microsoft Windows RPC service affecting the DCOM interface, primarily exposed on port 135. ISS said exploit code was already circulating and that widespread scanning and exploitation had been observed against affected Windows systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.