CVE-2005-0051
The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 46.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 46.57% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows xp
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/14189
- http://securitytracker.com/id?1013112
- http://www.kb.cert.org/vuls/id/939074Patch, US Government Resource
- http://www.securityfocus.com/bid/12486
- http://www.us-cert.gov/cas/techalerts/TA05-039A.htmlPatch, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19093
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2292
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3055
- http://secunia.com/advisories/14189
- http://securitytracker.com/id?1013112
- http://www.kb.cert.org/vuls/id/939074Patch, US Government Resource
- http://www.securityfocus.com/bid/12486
- http://www.us-cert.gov/cas/techalerts/TA05-039A.htmlPatch, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19093
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2292
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3055
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.