First published: Sun Dec 04 2005(Updated: )
** DISPUTED ** NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =web | |
Microsoft Windows 2003 Server | =enterprise | |
Microsoft Windows XP | =gold | |
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2003 Server | =r2-sp1 | |
Microsoft Windows 2003 Server | =web-sp1 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows 2003 Server | =standard-sp1 | |
Microsoft Windows 2003 Server | =enterprise-sp1 | |
Microsoft Windows 2003 Server | =standard | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2000 | =sp3 | |
=sp1 | ||
=sp2 | ||
=sp3 | ||
=sp4 | ||
=enterprise | ||
=enterprise-sp1 | ||
=r2 | ||
=r2-sp1 | ||
=standard | ||
=standard-sp1 | ||
=web | ||
=web-sp1 | ||
=gold | ||
=sp1 | ||
=sp1 | ||
=sp2 | ||
=sp2 | ||
=sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3981 has been disputed in severity by third-party analysts, indicating potential variability in its risk assessment.
Mitigation for CVE-2005-3981 may involve restricting local user privileges and monitoring process activities.
CVE-2005-3981 affects several Microsoft operating systems including Windows XP, 2000, and 2003 with specific service packs.
CVE-2005-3981 may allow local users to terminate writable processes using specific arguments via the CreateRemoteThread function.
There is no official patch for CVE-2005-3981 due to its disputed nature and related concerns.