{"api_version":"1","generated_at":"2026-07-23T09:47:06+00:00","cve":"CVE-2005-2119","urls":{"html":"https://cve.report/CVE-2005-2119","api":"https://cve.report/api/cve/CVE-2005-2119.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2119","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2119"},"summary":{"title":"CVE-2005-2119","description":"The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.","state":"PUBLISHED","assigner":"microsoft","published_at":"2005-10-12 13:04:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/17161","name":"http://secunia.com/advisories/17161","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Microsoft Windows MSDTC and COM+ Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-051","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-051","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS05-051 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17509","name":"http://secunia.com/advisories/17509","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Nortel CallPilot Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/180868","name":"http://www.kb.cert.org/vuls/id/180868","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#180868","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A551","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A551","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/18828","name":"http://www.osvdb.org/18828","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/17172","name":"http://secunia.com/advisories/17172","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Avaya Various Products Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17223","name":"http://secunia.com/advisories/17223","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Nortel Centrex IP Client Manager Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA05-284A.html","name":"http://www.us-cert.gov/cas/techalerts/TA05-284A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA05-284A -- Microsoft Windows, Internet Explorer, and Exchange Server Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/73","name":"http://securityreason.com/securityalert/73","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.eeye.com/html/research/advisories/AD20051011b.html","name":"http://www.eeye.com/html/research/advisories/AD20051011b.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Network Security, Vulnerability Assessment, Intrusion Prevention","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015037","name":"http://securitytracker.com/id?1015037","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Microsoft Windows Buffer Overflows in MSDTC and COM+ Let Remote Users Execute Arbitrary Code and Local User Gain Elevated Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15056","name":"http://www.securityfocus.com/bid/15056","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Windows MSDTC Memory Corruption Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf","name":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1071","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1071","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1452","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1452","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2119","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2119","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2119","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"*","cpe7":"sp4","cpe8":"*","cpe9":"fr","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2119","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"64-bit","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2119","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"itanium","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2119","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"r2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2119","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"sp1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2119","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"sp1","cpe7":"*","cpe8":"itanium","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2119","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"*","cpe8":"64-bit","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2119","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"sp1","cpe8":"tablet_pc","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2119","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"sp2","cpe8":"tablet_pc","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:15:37.502Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"17161","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17161"},{"name":"MS05-051","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-051"},{"name":"1015037","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015037"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"},{"name":"oval:org.mitre.oval:def:1452","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1452"},{"name":"VU#180868","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/180868"},{"name":"oval:org.mitre.oval:def:1071","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1071"},{"name":"17223","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17223"},{"name":"oval:org.mitre.oval:def:551","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A551"},{"name":"73","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/73"},{"name":"18828","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/18828"},{"name":"17172","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17172"},{"name":"15056","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15056"},{"name":"17509","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17509"},{"name":"AD20051011b","tags":["third-party-advisory","x_refsource_EEYE","x_transferred"],"url":"http://www.eeye.com/html/research/advisories/AD20051011b.html"},{"name":"TA05-284A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA05-284A.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-10-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"17161","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17161"},{"name":"MS05-051","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-051"},{"name":"1015037","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015037"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"},{"name":"oval:org.mitre.oval:def:1452","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1452"},{"name":"VU#180868","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/180868"},{"name":"oval:org.mitre.oval:def:1071","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1071"},{"name":"17223","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17223"},{"name":"oval:org.mitre.oval:def:551","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A551"},{"name":"73","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/73"},{"name":"18828","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/18828"},{"name":"17172","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17172"},{"name":"15056","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15056"},{"name":"17509","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17509"},{"name":"AD20051011b","tags":["third-party-advisory","x_refsource_EEYE"],"url":"http://www.eeye.com/html/research/advisories/AD20051011b.html"},{"name":"TA05-284A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA05-284A.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2005-2119","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"17161","refsource":"SECUNIA","url":"http://secunia.com/advisories/17161"},{"name":"MS05-051","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-051"},{"name":"1015037","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015037"},{"name":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf","refsource":"CONFIRM","url":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"},{"name":"oval:org.mitre.oval:def:1452","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1452"},{"name":"VU#180868","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/180868"},{"name":"oval:org.mitre.oval:def:1071","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1071"},{"name":"17223","refsource":"SECUNIA","url":"http://secunia.com/advisories/17223"},{"name":"oval:org.mitre.oval:def:551","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A551"},{"name":"73","refsource":"SREASON","url":"http://securityreason.com/securityalert/73"},{"name":"18828","refsource":"OSVDB","url":"http://www.osvdb.org/18828"},{"name":"17172","refsource":"SECUNIA","url":"http://secunia.com/advisories/17172"},{"name":"15056","refsource":"BID","url":"http://www.securityfocus.com/bid/15056"},{"name":"17509","refsource":"SECUNIA","url":"http://secunia.com/advisories/17509"},{"name":"AD20051011b","refsource":"EEYE","url":"http://www.eeye.com/html/research/advisories/AD20051011b.html"},{"name":"TA05-284A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA05-284A.html"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2005-2119","datePublished":"2005-10-11T04:00:00.000Z","dateReserved":"2005-07-02T00:00:00.000Z","dateUpdated":"2024-08-07T22:15:37.502Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-10-12 13:04:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:*","matchCriteriaId":"330B6798-5380-44AD-9B52-DF5955FA832C"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:64-bit:*:*:*:*:*:*:*","matchCriteriaId":"D2CA1674-A8A0-479A-9D80-344D3C563A24"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:itanium:*:*:*:*:*:*:*","matchCriteriaId":"0808041A-CE1A-433A-9C2B-019097CCFB0C"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*","matchCriteriaId":"4E7FD818-322D-4089-A644-360C33943D29"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*","matchCriteriaId":"644E2E89-F3E3-4383-B460-424D724EE62F"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*","matchCriteriaId":"7D11FC8D-59DD-4CAC-B4D3-DABB7A9903F1"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*","matchCriteriaId":"91D6D065-A28D-49DA-B7F4-38421FF86498"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*","matchCriteriaId":"B9687E6C-EDE9-42E4-93D0-C4144FEC917A"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*","matchCriteriaId":"FB2BE2DE-7B06-47ED-A674-15D45448F357"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2119","Ordinal":"1","Title":"CVE-2005-2119","CVE":"CVE-2005-2119","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2119","Ordinal":"1","NoteData":"The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.","Type":"Description","Title":"CVE-2005-2119"},{"CveYear":"2005","CveId":"2119","Ordinal":"2","NoteData":"2005-10-11","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2119","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}