The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.kb.cert.org/vuls/id/130433 - Patch, US Government Resource | |
References | () http://www.us-cert.gov/cas/techalerts/TA05-039A.html - Patch, US Government Resource | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-010 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/19101 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2568 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3582 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4786 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A644 - |
Information
Published : 2005-05-02 04:00
Updated : 2024-11-20 23:54
NVD link : CVE-2005-0050
Mitre link : CVE-2005-0050
CVE.ORG link : CVE-2005-0050
JSON object : View
Products Affected
microsoft
- windows_2000
- windows_nt
- windows_2003_server
CWE
CWE-20
Improper Input Validation