{"api_version":"1","generated_at":"2026-07-23T08:57:54+00:00","cve":"CVE-2005-2150","urls":{"html":"https://cve.report/CVE-2005-2150","api":"https://cve.report/api/cve/CVE-2005-2150.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2150","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2150"},"summary":{"title":"CVE-2005-2150","description":"Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-07-11 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://securitytracker.com/id?1014417","name":"http://securitytracker.com/id?1014417","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Windows Named Pipe NULL Session Bugs in svcctl and eventlog RPC Interfaces Disclose Information to Remote Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21288","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21288","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21286","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21286","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=112076409813099&w=2","name":"http://marc.info/?l=bugtraq&m=112076409813099&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/14189","name":"http://secunia.com/advisories/14189","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Windows Anonymous Named Pipe Connection Information Disclosure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14178","name":"http://www.securityfocus.com/bid/14178","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Windows MSRPC Eventlog Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/14177","name":"http://www.securityfocus.com/bid/14177","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Windows MSRPC SVCCTL Service Enumeration Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.hsc.fr/ressources/presentations/null_sessions/","name":"http://www.hsc.fr/ressources/presentations/null_sessions/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2150","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2150","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2150","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2150","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_nt","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:15:37.455Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.hsc.fr/ressources/presentations/null_sessions/"},{"name":"20050707 NULL sessions vulnerabilities using alternate named pipes","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112076409813099&w=2"},{"name":"1014417","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014417"},{"name":"14177","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14177"},{"name":"win-name-pipe-null-information-disclosure(21286)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21286"},{"name":"14178","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14178"},{"name":"win-pipe-null-eventlog-information-disclosure(21288)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21288"},{"name":"14189","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/14189"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-07-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.hsc.fr/ressources/presentations/null_sessions/"},{"name":"20050707 NULL sessions vulnerabilities using alternate named pipes","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112076409813099&w=2"},{"name":"1014417","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014417"},{"name":"14177","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14177"},{"name":"win-name-pipe-null-information-disclosure(21286)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21286"},{"name":"14178","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14178"},{"name":"win-pipe-null-eventlog-information-disclosure(21288)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21288"},{"name":"14189","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/14189"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2150","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.hsc.fr/ressources/presentations/null_sessions/","refsource":"MISC","url":"http://www.hsc.fr/ressources/presentations/null_sessions/"},{"name":"20050707 NULL sessions vulnerabilities using alternate named pipes","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112076409813099&w=2"},{"name":"1014417","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014417"},{"name":"14177","refsource":"BID","url":"http://www.securityfocus.com/bid/14177"},{"name":"win-name-pipe-null-information-disclosure(21286)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21286"},{"name":"14178","refsource":"BID","url":"http://www.securityfocus.com/bid/14178"},{"name":"win-pipe-null-eventlog-information-disclosure(21288)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21288"},{"name":"14189","refsource":"SECUNIA","url":"http://secunia.com/advisories/14189"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2150","datePublished":"2005-07-11T04:00:00.000Z","dateReserved":"2005-07-06T00:00:00.000Z","dateUpdated":"2024-08-07T22:15:37.455Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-07-11 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*","matchCriteriaId":"4E545C63-FE9C-4CA1-AF0F-D999D84D2AFD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*","matchCriteriaId":"E53CDA8E-50A8-4509-B070-CCA5604FFB21"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2150","Ordinal":"1","Title":"CVE-2005-2150","CVE":"CVE-2005-2150","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2150","Ordinal":"1","NoteData":"Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.","Type":"Description","Title":"CVE-2005-2150"},{"CveYear":"2005","CveId":"2150","Ordinal":"2","NoteData":"2005-07-11","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2150","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}