Vulnerability record · CVE-2005-0051 · published 2 May 2005
CVE-2005-0051: Windows XP Server Service Named Pipe Anonymous Logon Information Disclosure
Microsoft · Windows Xp
The Server service (srvsvc.dll) in Windows XP SP1 and SP2 fails to properly authenticate an anonymous logon over a named pipe, allowing remote attackers to obtain sensitive information about users accessing resources. This is an information disclosure flaw in a core Windows service, and the record does not specify affected versions beyond XP SP1 and SP2.
Description
The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote information disclosure with a high EPSS percentile, though the record lacks confirmed in-the-wild exploitation and the affected platform is legacy.
What it is
The Server service (srvsvc.dll) in Windows XP SP1 and SP2 fails to properly authenticate an anonymous logon over a named pipe, allowing remote attackers to obtain sensitive information about users accessing resources. This is an information disclosure flaw in a core Windows service, and the record does not specify affected versions beyond XP SP1 and SP2.
Impact
An attacker gains knowledge of which users are accessing resources on the target host, which can support reconnaissance and targeting of accounts. The CVSS vector also lists partial integrity and availability impact, but the description only substantiates the confidentiality loss.
Attack surface
Reachable remotely over the network via the Server service named pipe, with no authentication required (anonymous logon) and no user interaction indicated. The CVSS vector AV:N/AC:L/Au:N is consistent with an unauthenticated remote path.
Exploitation
The record is not listed in CISA KEV and contains no exploit tags, but EPSS shows a 30-day probability of 0.4657 (98.8th percentile), indicating elevated predicted exploitation activity. No public exploit code or in-the-wild use is confirmed by the supplied data.
What to do
- Apply the Microsoft security update MS05-007 referenced in the record, which is the vendor patch for this flaw.
- Restrict anonymous access to named pipes and the Server service where operationally feasible.
- Block SMB/NetBIOS ports (139, 445) at network boundaries and limit lateral reachability of the Server service.
- Disable or harden the Server service on hosts that do not require file or print sharing.
- Retire or isolate Windows XP SP1/SP2 systems, which are long past end of support.
Detection
- Monitor for anonymous logon events (Windows Security event 528/4624 with logon type 3 and null/anonymous account) against the Server service.
- Alert on named pipe access to srvsvc from unexpected or external source addresses.
- Baseline and review SMB/NetBIOS connection attempts to hosts running Windows XP.
- Correlate anonymous SMB sessions with subsequent enumeration of user or share information.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0051 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0051), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.