CVE-2005-0904: Input Validation
Published Mar 29, 2005
·Updated
Remote Desktop in Windows XP SP1 does not verify the "Force shutdown from a remote system" setting, which allows remote attackers to shut down the system by executing TSShutdn.exe.
Affected Software
1 affected component
Microsoft Windows XP=sp1
Event History
Mar 29, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0904?
CVE-2005-0904 has a moderate severity, as it allows remote attackers to shut down the system.
2
How do I fix CVE-2005-0904?
To fix CVE-2005-0904, it is recommended to upgrade to a later service pack beyond Windows XP SP1.
3
What vulnerabilities does CVE-2005-0904 expose my system to?
CVE-2005-0904 exposes your system to unauthorized remote shutdowns, resulting in potential downtime.
4
Which versions of Windows are affected by CVE-2005-0904?
Only Windows XP SP1 is affected by CVE-2005-0904.
5
What method do attackers use in CVE-2005-0904?
Attackers exploit CVE-2005-0904 by executing TSShutdn.exe without proper verification of shutdown settings.