← back
CVE-2005-2120

CVE-2005-2120

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 62%
from disclosure to weapon8 days
Published on NVDOct 13
1st PoC+8d
exploitation probability
62%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.