First published: Thu Oct 13 2005(Updated: )
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2120 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2005-2120, users should apply the latest security updates from Microsoft for Windows 2000 SP4 and Windows XP SP1/SP2.
CVE-2005-2120 affects Microsoft Windows 2000 SP4 and Microsoft Windows XP SP1 and SP2.
CVE-2005-2120 can be exploited by both local and remote authenticated attackers.
CVE-2005-2120 is a stack-based buffer overflow vulnerability in the Plug and Play service.