AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2005-2120

MEDIUM · CVSS 6.5 EPSS 61.97%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-10-13 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Microsoft, Windows. Its EPSS score suggests a 62.0% probability of exploitation in the next 30 days. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2005-2120
Severity
MEDIUM
CVSS
6.5
EPSS
61.97%
Microsoft Windows

Original NVD Description

Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.