CVE-2005-0050
The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 46.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 46.69% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/windows 2000 · microsoft/windows 2003 server · microsoft/windows nt
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/130433Patch, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA05-039A.htmlPatch, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-010
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19101
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2568
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3582
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4786
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A644
- http://www.kb.cert.org/vuls/id/130433Patch, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA05-039A.htmlPatch, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-010
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19101
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2568
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3582
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4786
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A644
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.