VulnerabilityModified
CVE-2005-1984
Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
HIGH 7.5EPSS 55.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 55.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 55.30% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows 2003 server · microsoft/windows xp
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/16356/Patch, Vendor Advisory
- http://securitytracker.com/id?1014638
- http://www.kb.cert.org/vuls/id/220821US Government Resource
- http://www.securityfocus.com/bid/14514
- http://www.us-cert.gov/cas/techalerts/TA05-221A.htmlPatch, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-043
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100077
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1045
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1405
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A256
- http://secunia.com/advisories/16356/Patch, Vendor Advisory
- http://securitytracker.com/id?1014638
- http://www.kb.cert.org/vuls/id/220821US Government Resource
- http://www.securityfocus.com/bid/14514
- http://www.us-cert.gov/cas/techalerts/TA05-221A.htmlPatch, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-043
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100077
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1045
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1405
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A256
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.