## https://sploitus.com/exploit?id=SAINT:F0CCBA79891EC69AFBE14E3B1AC55891
Added: 06/12/2007
CVE: [CVE-2005-0058](<https://vulners.com/cve/CVE-2005-0058>)
BID: [14518](<http://www.securityfocus.com/bid/14518>)
OSVDB: [18606](<http://www.osvdb.org/18606>)
### Background
The Windows [Telephony API](<http://msdn2.microsoft.com/en-us/library/aa922068.aspx>) (TAPI) provides telecommunications support for Windows applications.
### Problem
A buffer overflow in the Windows Telephony API allows local attackers to execute commands with administrative privileges.
### Resolution
Apply the patch referenced in [Microsoft Security Bulletin 05-040](<http://www.microsoft.com/technet/security/bulletin/ms05-040.mspx>).
### References
<http://www.microsoft.com/technet/security/bulletin/ms05-040.mspx>
### Limitations
The Telephony service must be running on the target in order for this exploit to succeed.
### Platforms
Windows 2000