CVE-2005-2120
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
- Affected products
- Windows 2000, Windows Xp
- Microsoft Windows 2000
- All versions
- Microsoft Windows Xp
- All versions
- Fix
- Available
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 62.0% (99th percentile)
- NVD status
- Modified
- Published
- 2005-10-13
CVE-2005-2120 at NVD
4 known exploits for CVE-2005-2120
Proof-of-concept code and exploit modules indexed by Sploitus