CVE-2005-4696

Microsoft Wireless Zero Configuration - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-4696. PoCs published by Laszlo Toth.

AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in the Wireless Zero Configuration Service (WZCSVC) on Windows XP SP2. It retrieves WPA pre-shared keys and WEP keys by interacting with the wzcsapi.dll RPC interface.

Description

The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key in plaintext in memory of the explorer process, which allows attackers with access to process memory to steal the keys and access the network.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Laszlo Toth · c++localwindows
https://www.exploit-db.com/exploits/26323

This exploit demonstrates an information disclosure vulnerability in the Wireless Zero Configuration Service (WZCSVC) on Windows XP SP2. It retrieves WPA pre-shared keys and WEP keys by interacting with the wzcsapi.dll RPC interface.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows XP SP2
No auth needed
Prerequisites: Local access to the target system
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/46
Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2005-10/0016.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/19873
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1970
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15008
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/26323/
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17064
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/22524

Scores

EPSS 0.0531
EPSS Percentile 90.3%

Details

Status published
Products (1)
microsoft/windows_xp (4 CPE variants)
Published Dec 31, 2005
Tracked Since Feb 18, 2026