VDB
CVE-2005-0063
CVE-2005-0063
PUBLISHED
CVSS 7.5 HIGH
The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.
EPSS 69.79% · 98.7th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
69.79%
98.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_2003_server | *, r2, standard |
| microsoft | windows_98 | |
| microsoft | windows_98se | |
| microsoft | windows_xp | |
| microsoft | windows_2000 | |
| microsoft | windows_me | |
| n/a | n/a | n/a |
Timeline
- Apr 13, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- oval:org.mitre.oval:def:3456 vdb
- MS05-016 vendor-advisory
- oval:org.mitre.oval:def:407 vdb
- 20050529 Spam exploiting MS05-016 mailing-list
- oval:org.mitre.oval:def:587 vdb
- http://www.securiteam.com/exploits/5YP0T0AFFW.html url
- 20050412 Microsoft MSHTA Script Execution Vulnerability third-party-advisory
- ADV-2005-0335 vdb
- oval:org.mitre.oval:def:573 vdb
- oval:org.mitre.oval:def:2184 vdb
- oval:org.mitre.oval:def:4710 vdb
- 13132 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2005-0063 advisory