VDB
CVE-2005-0047
CVE-2005-0047
PUBLISHED
CVSS 7.199999809265137 HIGH
Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."
EPSS 8.95% · 92.7th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
8.95%
92.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_2000 | |
| n/a | n/a | n/a |
| microsoft | windows_2003_server | enterprise, enterprise_64-bit, r2 |
| microsoft | windows_xp |
Timeline
- Feb 8, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- oval:org.mitre.oval:def:901 vdb
- oval:org.mitre.oval:def:1159 vdb
- TA05-039A third-party-advisory
- http://www.argeniss.com/research/SSExploit.c url
- MS05-012 vendor-advisory
- 20050530 [Argeniss] MS05-012 Exploit mailing-list
- oval:org.mitre.oval:def:2351 vdb
- win-com-gain-privileges(19105) vdb
- VU#597889 third-party-advisory
- oval:org.mitre.oval:def:2892 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2005-0047 advisory