Vulnerability Name:
CVE-2005-0059 (CCN-19829)
Assigned:
2005-04-12
Published:
2005-04-12
Updated:
2019-04-30
Summary:
Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
CVSS v3 Severity:
10.0 Critical
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Changed
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
CVSS v2 Severity:
10.0 High
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
)
8.3 High
(Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
10.0 High
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
)
8.3 High
(CCN Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2005-0059
Source: CCN
Type: CIAC INFORMATION BULLETIN P-178
Vulnerability in Message Queuing (892944)
Source: CCN
Type: US-CERT VU#763513
Microsoft Message Queuing vulnerable to buffer overflow
Source: CCN
Type: Microsoft Security Bulletin MS05-017
Vulnerability in Message Queuing Could Allow Code Execution (892944)
Source: CCN
Type: Microsoft Security Bulletin MS07-065
Vulnerability in Message Queuing Service Could Allow Remote Code Execution (937894)
Source: CCN
Type: Microsoft Security Bulletin MS08-065
Vulnerability in Message Queuing Could Allow Remote Code Execution (951071)
Source: CCN
Type: BID-13112
Microsoft Windows Message Queuing Remote Buffer Overflow Vulnerability
Source: MS
Type: UNKNOWN
MS05-017
Source: XF
Type: UNKNOWN
win-message-queue-bo(19829)
Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:4384
Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:4988
Vulnerable Configuration:
Configuration 1
:
cpe:/o:microsoft:windows_2000:*:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_98:*:gold:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_98se:*:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:*:embedded:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:*:home:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:sp1:64-bit:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:sp1:embedded:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*
Configuration CCN 1
:
cpe:/o:microsoft:windows_98:*:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_98se:*:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_2000:-:sp3:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:-:sp1:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.mitre.oval:def:4384
V
Windows XP Message Queuing Buffer Overflow
2011-05-16
oval:org.mitre.oval:def:4988
V
Windows 2000 Message Queuing Buffer Overflow
2011-05-16
BACK
microsoft
windows 2000 *
microsoft
windows 2000 * sp1
microsoft
windows 2000 * sp2
microsoft
windows 2000 * sp3
microsoft
windows 2000 * sp4
microsoft
windows 98 * gold
microsoft
windows 98se *
microsoft
windows xp *
microsoft
windows xp *
microsoft
windows xp *
microsoft
windows xp *
microsoft
windows xp * gold
microsoft
windows xp * sp1
microsoft
windows xp * sp1
microsoft
windows xp * sp1
microsoft
windows xp * sp1
microsoft
windows xp * sp2
microsoft
windows 98 *
microsoft
windows 98se *
microsoft
windows 2000 - sp3
microsoft
windows xp - sp1
microsoft
windows 2000 - sp4