Vulnerability Name: | CVE-2005-0551 (CCN-19836) | ||||||||||||||||||||
Assigned: | 2005-04-12 | ||||||||||||||||||||
Published: | 2005-04-12 | ||||||||||||||||||||
Updated: | 2018-10-12 | ||||||||||||||||||||
Summary: | Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value. | ||||||||||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2005-0551 Source: CCN Type: CIAC INFORMATION BULLETIN P-180 Vulnerabilities in Windows Kernel (890859) Source: IDEFENSE Type: Patch, Vendor Advisory 20050412 Microsoft Windows CSRSS.EXE Stack Overflow Vulnerability Source: CCN Type: US-CERT VU#259197 Microsoft Client Server Runtime System Vulnerability Source: CCN Type: Microsoft Security Bulletin MS05-018 Vulnerability in Windows Kernel Could Allow Elevation of Privilege and Denial of Service (890859) Source: CCN Type: BID-13115 Microsoft Windows Kernel CSRSS Local Privilege Escalation Vulnerability Source: MS Type: UNKNOWN MS05-018 Source: XF Type: UNKNOWN windows-csrss-gain-control(19836) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1822 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:266 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:3544 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:777 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |