{"api_version":"1","generated_at":"2026-07-23T05:45:11+00:00","cve":"CVE-2005-2120","urls":{"html":"https://cve.report/CVE-2005-2120","api":"https://cve.report/api/cve/CVE-2005-2120.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2120","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2120"},"summary":{"title":"CVE-2005-2120","description":"Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of \"\\\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.","state":"PUBLISHED","assigner":"microsoft","published_at":"2005-10-13 10:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.osvdb.org/18830","name":"http://www.osvdb.org/18830","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/15065","name":"http://www.securityfocus.com/bid/15065","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"Microsoft Windows Plug And Play UMPNPMGR.DLL wsprintfW Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1244","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1244","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015042","name":"http://securitytracker.com/id?1015042","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"SecurityTracker.com Archives - Microsoft Windows Plug and Play Buffer Overflow Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17166","name":"http://secunia.com/advisories/17166","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Microsoft Windows Plug-and-Play Service Arbitrary Code Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1328","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1328","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1519","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1519","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/71","name":"http://securityreason.com/securityalert/71","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17172","name":"http://secunia.com/advisories/17172","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Avaya Various Products Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17223","name":"http://secunia.com/advisories/17223","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Nortel Centrex IP Client Manager Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/214572","name":"http://www.kb.cert.org/vuls/id/214572","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#214572","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA05-284A.html","name":"http://www.us-cert.gov/cas/techalerts/TA05-284A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA05-284A -- Microsoft Windows, Internet Explorer, and Exchange Server Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-047","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-047","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS05-047 - Important | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.eeye.com/html/research/advisories/AD20051011c.html","name":"http://www.eeye.com/html/research/advisories/AD20051011c.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Network Security, Vulnerability Assessment, Intrusion Prevention","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf","name":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2120","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2120","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2120","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"*","cpe7":"sp4","cpe8":"*","cpe9":"fr","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2120","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"sp1","cpe8":"tablet_pc","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2120","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"sp2","cpe8":"tablet_pc","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:15:37.420Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"15065","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15065"},{"name":"17166","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17166"},{"name":"MS05-047","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-047"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"},{"name":"17223","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17223"},{"name":"oval:org.mitre.oval:def:1244","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1244"},{"name":"1015042","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015042"},{"name":"AD20051011c","tags":["third-party-advisory","x_refsource_EEYE","x_transferred"],"url":"http://www.eeye.com/html/research/advisories/AD20051011c.html"},{"name":"71","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/71"},{"name":"18830","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/18830"},{"name":"17172","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17172"},{"name":"VU#214572","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/214572"},{"name":"oval:org.mitre.oval:def:1328","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1328"},{"name":"oval:org.mitre.oval:def:1519","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1519"},{"name":"TA05-284A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA05-284A.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-10-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of \"\\\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"15065","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15065"},{"name":"17166","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17166"},{"name":"MS05-047","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-047"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"},{"name":"17223","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17223"},{"name":"oval:org.mitre.oval:def:1244","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1244"},{"name":"1015042","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015042"},{"name":"AD20051011c","tags":["third-party-advisory","x_refsource_EEYE"],"url":"http://www.eeye.com/html/research/advisories/AD20051011c.html"},{"name":"71","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/71"},{"name":"18830","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/18830"},{"name":"17172","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17172"},{"name":"VU#214572","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/214572"},{"name":"oval:org.mitre.oval:def:1328","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1328"},{"name":"oval:org.mitre.oval:def:1519","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1519"},{"name":"TA05-284A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA05-284A.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2005-2120","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of \"\\\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"15065","refsource":"BID","url":"http://www.securityfocus.com/bid/15065"},{"name":"17166","refsource":"SECUNIA","url":"http://secunia.com/advisories/17166"},{"name":"MS05-047","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-047"},{"name":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf","refsource":"CONFIRM","url":"http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"},{"name":"17223","refsource":"SECUNIA","url":"http://secunia.com/advisories/17223"},{"name":"oval:org.mitre.oval:def:1244","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1244"},{"name":"1015042","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015042"},{"name":"AD20051011c","refsource":"EEYE","url":"http://www.eeye.com/html/research/advisories/AD20051011c.html"},{"name":"71","refsource":"SREASON","url":"http://securityreason.com/securityalert/71"},{"name":"18830","refsource":"OSVDB","url":"http://www.osvdb.org/18830"},{"name":"17172","refsource":"SECUNIA","url":"http://secunia.com/advisories/17172"},{"name":"VU#214572","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/214572"},{"name":"oval:org.mitre.oval:def:1328","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1328"},{"name":"oval:org.mitre.oval:def:1519","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1519"},{"name":"TA05-284A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA05-284A.html"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2005-2120","datePublished":"2005-10-13T04:00:00.000Z","dateReserved":"2005-07-02T00:00:00.000Z","dateUpdated":"2024-08-07T22:15:37.420Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-10-13 10:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:*","matchCriteriaId":"330B6798-5380-44AD-9B52-DF5955FA832C"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*","matchCriteriaId":"B9687E6C-EDE9-42E4-93D0-C4144FEC917A"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*","matchCriteriaId":"FB2BE2DE-7B06-47ED-A674-15D45448F357"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2120","Ordinal":"1","Title":"CVE-2005-2120","CVE":"CVE-2005-2120","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2120","Ordinal":"1","NoteData":"Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of \"\\\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.","Type":"Description","Title":"CVE-2005-2120"},{"CveYear":"2005","CveId":"2120","Ordinal":"2","NoteData":"2005-10-13","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2120","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}