CVE-2005-1214: Medium severity Microsoft Windows 2003 Server vulnerability
Published Jun 14, 2005
·Updated
Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.
Affected Software
49 affected components
Microsoft Windows 2003 Server=64-bit
Microsoft Windows 2000 Terminal Services=sp1
Microsoft Windows 2003 Server=web-sp1_beta_1
Microsoft Windows XP=sp1
Microsoft Windows 2003 Server=web
Microsoft Windows 2003 Server=enterprise
Microsoft Windows XP
Microsoft Windows 2003 Server=enterprise_64-bit
Microsoft Windows 2003 Server=enterprise-sp1_beta_1
Microsoft Windows XP=gold
Microsoft Windows 2000
Microsoft Windows Me
Microsoft Windows XP
Microsoft Windows 2003 Server=standard_64-bit
Microsoft Windows 2003 Server=datacenter_64-bit-sp1
Microsoft Windows 2000=sp4
Microsoft Windows XP=sp2
Microsoft Windows 2003 Server=datacenter_64-bit-sp1_beta_1
Microsoft Windows XP=sp1
Microsoft Windows XP
Microsoft Windows XP=sp1
Microsoft Windows 98SE
Microsoft Windows 2000=sp2
Microsoft Windows 2003 Server=standard-sp1_beta_1
Microsoft Windows XP=sp1
Microsoft Windows 2003 Server=r2-sp1
Microsoft Windows 2003 Server=enterprise_64-bit-sp1
Microsoft Windows 2000 Terminal Services=sp3
Microsoft Windows 2003 Server=r2
Microsoft Windows 2003 Server=r2-sp1_beta_1
Microsoft Windows 2003 Server=web-sp1
Microsoft Windows 2003 Server=r2
Microsoft Windows 2000=sp1
Microsoft Windows XP=sp2
Microsoft Windows XP
Microsoft Windows 2003 Server=standard-sp1
Microsoft Windows Me
Microsoft Windows 2003 Server=enterprise-sp1
Microsoft Windows 2000=sp4
Microsoft Windows XP=sp1
Microsoft Windows 2003 Server=standard
Microsoft Windows XP=sp2
Microsoft Windows 2000 Terminal Services
Microsoft Windows 2003 Server=enterprise_64-bit-sp1_beta_1
Microsoft Windows 98=gold
Microsoft Windows 2000 Terminal Services=sp2
Microsoft Windows 2003 Server=r2
Microsoft Windows XP=gold
Microsoft Windows 2000=sp3
Remediation
Patch Available
Event History
Jun 14, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1214?
CVE-2005-1214 is considered a critical vulnerability because it allows remote attackers to run arbitrary code.
2
How do I fix CVE-2005-1214?
To fix CVE-2005-1214, apply the latest security updates provided by Microsoft for the affected software.
3
Which versions of Microsoft Windows are affected by CVE-2005-1214?
CVE-2005-1214 affects various versions of Microsoft Windows, including Windows 2000, Windows XP, and Windows Server 2003.
4
What type of attack does CVE-2005-1214 facilitate?
CVE-2005-1214 facilitates local or remote code execution by spoofing security prompts on malicious web pages.
5
Is there a workaround for CVE-2005-1214 if I cannot apply the patch?
As a temporary workaround for CVE-2005-1214, consider disabling the Microsoft Agent service or restricting internet access.