Vulnerabilities > CVE-2005-0047 - Unspecified vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 21 |
Exploit-Db
description | MS Windows COM Structured Storage Local Exploit (MS05-012). CVE-2005-0047. Local exploit for windows platform |
id | EDB-ID:1019 |
last seen | 2016-01-31 |
modified | 2005-05-31 |
published | 2005-05-31 |
reporter | Cesar Cerrudo |
source | https://www.exploit-db.com/download/1019/ |
title | Microsoft Windows - COM Structured Storage Local Exploit MS05-012 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS05-012.NASL |
description | The remote host is running a version of Windows that is affected by two vulnerabilities when dealing with OLE and/or COM. These vulnerabilities could allow a local user to escalate his privileges and allow a remote user to execute arbitrary code on the remote host. To exploit these flaws, an attacker would need to send a specially crafted document to a victim on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 16327 |
published | 2005-02-08 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/16327 |
title | MS05-012: Vulnerability in OLE and COM Could Allow Code Execution (873333) |
code |
|
Oval
accepted 2011-05-16T04:00:26.376-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Andrew Buttner organization The MITRE Corporation name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability." family windows id oval:org.mitre.oval:def:1159 status accepted submitted 2005-02-15T12:00:00.000-04:00 title Windows 2000 COM Structured Storage Vulnerability version 71 accepted 2011-05-16T04:02:29.213-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Dragos Prisaca organization Gideon Technologies, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability." family windows id oval:org.mitre.oval:def:2351 status accepted submitted 2005-02-15T12:00:00.000-04:00 title Windows XP,SP2 COM Structured Storage Vulnerability version 70 accepted 2011-05-16T04:02:38.881-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability." family windows id oval:org.mitre.oval:def:2892 status accepted submitted 2005-03-29T12:00:00.000-04:00 title Windows XP,SP1 COM Structured Storage Vulnerability version 69 accepted 2005-04-13T12:15:00.000-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation
description Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability." family windows id oval:org.mitre.oval:def:901 status accepted submitted 2005-02-15T12:00:00.000-04:00 title Server 2003 COM Structured Storage Vulnerability version 66
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:5342 |
last seen | 2017-11-19 |
modified | 2006-10-28 |
published | 2006-10-28 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-5342 |
title | MS Windows COM Structured Storage Local Exploit (MS05-012) |
References
- http://www.us-cert.gov/cas/techalerts/TA05-039A.html
- http://www.kb.cert.org/vuls/id/597889
- http://www.argeniss.com/research/SSExploit.c
- http://marc.info/?l=bugtraq&m=111755870828817&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19105
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A901
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2892
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2351
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1159
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-012