VulnerabilityModified
CVE-2005-0059
Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
HIGH 10.0EPSS 73.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 73.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 73.27% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows 98 · microsoft/windows 98se · microsoft/windows xp
- Source
- cve@mitre.org
References
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-017
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4384
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4988
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-017
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4384
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4988
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.