Vulnerability record · CVE-2005-0050 · published 2 May 2005
CVE-2005-0050: Windows License Logging Service buffer overflow via unvalidated message length
Microsoft · Windows 2000
The License Logging service in Windows NT Server, Windows 2000 Server and Windows Server 2003 fails to validate the length of messages, producing an unchecked buffer. A remote, unauthenticated attacker can crash the service and possibly execute arbitrary code, making this a network-reachable, pre-authentication flaw on legacy server platforms.
Description
The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with a network, unauthenticated vector and possible code execution on server operating systems, combined with a very high EPSS percentile, warrants critical handling despite the absence of KEV listing.
What it is
The License Logging service in Windows NT Server, Windows 2000 Server and Windows Server 2003 fails to validate the length of messages, producing an unchecked buffer. A remote, unauthenticated attacker can crash the service and possibly execute arbitrary code, making this a network-reachable, pre-authentication flaw on legacy server platforms.
Impact
An attacker can cause a denial of service by crashing the License Logging service and may be able to execute arbitrary code in the service's context, potentially gaining system-level control of the host.
Attack surface
Reached over the network via the License Logging service interface, as reflected by the AV:N/AC:L/Au:N vector; no authentication or user interaction is required per the CVSS vector and description.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is 0.46691 (98.8th percentile), indicating a high predicted likelihood of exploitation activity.
What to do
- Apply the Microsoft security update for MS05-010 (the referenced patch) to affected Windows NT Server, Windows 2000 Server and Windows Server 2003 systems.
- Disable or stop the License Logging service where it is not required, since the flaw lives in that service.
- Block or restrict network access to the License Logging service ports at host and perimeter firewalls.
- Retire or isolate unsupported legacy Windows NT and Windows 2000 Server hosts that cannot be patched.
Detection
- Monitor for unexpected crashes or restarts of the License Logging service (llssrv) on affected servers.
- Alert on anomalous network traffic to the License Logging service port from untrusted sources.
- Review Windows event logs for service failure and application error entries tied to the License Logging service around suspected activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0050 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0050), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.