CVE-2005-1987
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 44.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 44.50% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- microsoft/exchange server · microsoft/windows 2000 · microsoft/windows server 2003 · microsoft/windows xp
- Source
- secure@microsoft.com
References
- http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0289.htmlBroken Link
- http://marc.info/?l=bugtraq&m=112915118302012&w=2Mailing List, Third Party Advisory
- http://secunia.com/advisories/17167Third Party Advisory
- http://securitytracker.com/id?1015038Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1015039Third Party Advisory, VDB Entry
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ907245
- http://www.kb.cert.org/vuls/id/883460Third Party Advisory, US Government Resource
- http://www.osvdb.org/19905Broken Link
- http://www.securityfocus.com/bid/15067Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA05-284A.htmlThird Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-048Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22495Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1130Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1201Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1406Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1420Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1515Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A581Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A848Third Party Advisory
- http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0289.htmlBroken Link
- http://marc.info/?l=bugtraq&m=112915118302012&w=2Mailing List, Third Party Advisory
- http://secunia.com/advisories/17167Third Party Advisory
- http://securitytracker.com/id?1015038Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1015039Third Party Advisory, VDB Entry
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ907245
- http://www.kb.cert.org/vuls/id/883460Third Party Advisory, US Government Resource
- http://www.osvdb.org/19905Broken Link
- http://www.securityfocus.com/bid/15067Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA05-284A.htmlThird Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-048Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.