CVE-2005-2118
Last modified
CVE-2005-2118 is a vulnerability of currently unknown severity. Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.. EPSS estimates a 46.29% chance of exploitation in the next 30 days.
Description
Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 2000 | All versions |
| Microsoft | Windows 2003 Server | r2 |
| Microsoft | Windows Xp | All versions |
References
- http://secunia.com/advisories/17168Vendor Advisory
- http://secunia.com/advisories/17172Vendor Advisory
- http://secunia.com/advisories/17223Vendor Advisory
- http://www.argeniss.com/research/MSBugPaper.pdfVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA05-284A.htmlThird Party Advisory, US Government Resource
- http://secunia.com/advisories/17168Vendor Advisory
- http://secunia.com/advisories/17172Vendor Advisory
- http://secunia.com/advisories/17223Vendor Advisory
- http://www.argeniss.com/research/MSBugPaper.pdfVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA05-284A.htmlThird Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-2118?
How severe is CVE-2005-2118?
How do I fix CVE-2005-2118?
Are you affected by CVE-2005-2118?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
