Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-1978Microsoft Windows 2003 Server vulnerability

5 documents4 sources
Severity
7.5HIGHNVD
EPSS
48.0%
top 2.27%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 12
Latest updateMay 1

Description

COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-qprj-8c78-j6w6: COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code2022-05-01
CVEList
CVE-2005-1978: COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code2005-10-11

💥Exploits & PoCs

2
Exploit-DB
CGX 20050314 - 'pathCGX' Remote File Inclusion2007-05-08
Exploit-DB
Microsoft Windows - DTC Remote (MS05-051) (2)2005-12-01