VDB
CVE-2005-1983
CVE-2005-1983
PUBLISHED
CVSS 10 CRITICAL
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
EPSS 87.98% · 99.5th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
87.98%
99.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_2000 | |
| microsoft | windows_xp | |
| n/a | n/a | n/a |
Timeline
- CVE Published
- Sep 7, 2007 VulnCheck KEV Exploitation
- Aug 30, 2010 PoC Published
- Jun 20, 2017 VulnCheck KEV Exploitation
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
References
- http://www.osvdb.org/18605 technical
- ADV-2005-1354 vdb
- oval:org.mitre.oval:def:497 vdb
- http://www.hsc.fr/ressources/presentations/null_sessions/ url
- http://www.frsirt.com/english/alerts/20050814.ZotobA.php url
- 20050811 Windows 2000 universal exploit for MS05-039 mailing-list
- VU#998653 third-party-advisory
- 14513 vdb
- oval:org.mitre.oval:def:267 vdb
- P-266 third-party-advisory
- 1014640 vdb
- win-plugandplay-bo(21602) vdb
- TA05-221A third-party-advisory
- 16372 third-party-advisory
- 20050809 Windows Plug and Play Remote Compromise third-party-advisory
- oval:org.mitre.oval:def:100073 vdb
- MS05-039 vendor-advisory
- oval:org.mitre.oval:def:160 vdb
- oval:org.mitre.oval:def:474 vdb
- oval:org.mitre.oval:def:783 vdb
…and 3 more