Vulnerability Name: | CVE-2005-2122 (CCN-22477) | ||||||||||||||||||||||||||||
Assigned: | 2005-10-11 | ||||||||||||||||||||||||||||
Published: | 2005-10-11 | ||||||||||||||||||||||||||||
Updated: | 2019-04-30 | ||||||||||||||||||||||||||||
Summary: | Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2005-2122 Source: CCN Type: SA17168 Microsoft Windows Shell and Web View Three Vulnerabilities Source: SECUNIA Type: Vendor Advisory 17168 Source: CCN Type: SA17172 Avaya Various Products Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 17172 Source: CCN Type: SA17223 Nortel Centrex IP Client Manager Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 17223 Source: CCN Type: SECTRACK ID: 1015040 Microsoft Windows Shell Bugs in Processing `.lnk` Files and in Web View Preview Mode Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1015040 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf Source: MISC Type: Vendor Advisory http://www.argeniss.com/research/MSBugPaper.pdf Source: CCN Type: US-CERT VU#922708 Microsoft Windows Shell fails to handle shortcut files properly Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#922708 Source: CCN Type: Microsoft Security Bulletin MS05-049 Vulnerabilities in Windows Shell Could Allow Remote Code Execution (900725) Source: BID Type: UNKNOWN 15069 Source: CCN Type: BID-15069 Microsoft Windows Malicious Shortcut Handling Remote Code Execution Vulnerability Source: CERT Type: Third Party Advisory, US Government Resource TA05-284A Source: MS Type: UNKNOWN MS05-049 Source: XF Type: UNKNOWN win-lnk-execute-code(22477) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1329 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1488 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1517 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1537 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1551 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:708 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |