Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-0551Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Windows 2003 Server

4 documents4 sources
Severity
10.0CRITICALNVD
EPSS
36.5%
top 2.87%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 2
Latest updateMay 1

Description

Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j4hg-5h89-fm7r: Stack-based buffer overflow in WINSRV2022-05-01
CVEList
CVE-2005-0551: Stack-based buffer overflow in WINSRV2005-04-13

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - CSRSS Privilege Escalation (MS05-018)2005-09-06