CVE-2005-0044
Microsoft Windows and Exchange OLE - Input Validation Remote Code Execution
Title source: manualDescription
The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."
References (8)
Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2917
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19109
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1180
Patch, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/927889
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA05-039A.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3568
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-012
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4499
Scores
EPSS
0.3336
EPSS Percentile
98.2%
Details
Status
published
Products (11)
microsoft/exchange_server
5.0
microsoft/windows_2000
(5 CPE variants)
microsoft/windows_2003_server
enterprise
microsoft/windows_2003_server
enterprise_64-bit
microsoft/windows_2003_server
r2 (2 CPE variants)
microsoft/windows_2003_server
standard
microsoft/windows_2003_server
web
microsoft/windows_98
microsoft/windows_98se
microsoft/windows_me
... and 1 more
Published
May 02, 2005
Tracked Since
Feb 18, 2026