CVE-2005-2150

N/A Unknown
Published: July 11, 2005 Modified: April 16, 2026
View on NVD

Description

Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://marc.info/?l=bugtraq&m=112076409813099&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/14189
Source: af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1014417
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.hsc.fr/ressources/presentations/null_sessions/
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/14177
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/14178
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/21286
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/21288
Source: af854a3a-2127-422b-91ae-364da2661108

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
26.8%
96th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

microsoft