CVE-2005-3177
CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors…
Does this matter?
Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.
Description
CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secure defaults, or cause security descriptors to be removed.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.38% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows 2003 server · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://support.microsoft.com/kb/831374Patch, Vendor Advisory
- http://support.microsoft.com/kb/831375Patch, Vendor Advisory
- http://support.microsoft.com/kb/900345
- http://support.microsoft.com/kb/831374Patch, Vendor Advisory
- http://support.microsoft.com/kb/831375Patch, Vendor Advisory
- http://support.microsoft.com/kb/900345
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.