← All CVEs

CVE-2005-2120

medium · 6.5

Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.

6.5
CVSS
62.0%
EPSS (exploit prob.)
99th
EPSS percentile
2005-10-13
Published

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-2120