First published: Wed Apr 13 2005(Updated: )
Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows XP | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0551 has a severity rating that indicates it allows local users to gain elevated privileges via a buffer overflow.
CVE-2005-0551 affects Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 environments through a vulnerability in the WINSRV.DLL file.
Local users on affected versions of Microsoft Windows are at risk from CVE-2005-0551 due to the potential to execute malicious applications.
Mitigation for CVE-2005-0551 includes applying the appropriate security patches provided by Microsoft to affected systems.
CVE-2005-0551 is primarily a concern for legacy systems still in operation, as it affects older versions of Microsoft Windows.