CVE-2005-3177

Microsoft Windows <Update Rollup 1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secure defaults, or cause security descriptors to be removed.

References (3)

Core 3
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/kb/831374
Patch, Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/kb/831375
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/kb/900345

Scores

EPSS 0.0138
EPSS Percentile 69.6%

Details

Status published
Products (3)
microsoft/windows_2000
microsoft/windows_2003_server r2
microsoft/windows_xp
Published Oct 06, 2005
Tracked Since Feb 18, 2026