← Vulnerability feed

Vulnerability record · CVE-2005-0051 · published 2 May 2005

CVE-2005-0051: Windows XP Server Service Named Pipe Anonymous Logon Information Disclosure

Microsoft · Windows Xp

The Server service (srvsvc.dll) in Windows XP SP1 and SP2 fails to properly authenticate an anonymous logon over a named pipe, allowing remote attackers to obtain sensitive information about users accessing resources. This is an information disclosure flaw in a core Windows service, and the record does not specify affected versions beyond XP SP1 and SP2.

7.5 CVSS 2.0 High EPSS 47% · top 1.2%
7.5CVSS 2.0 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated remote information disclosure with a high EPSS percentile, though the record lacks confirmed in-the-wild exploitation and the affected platform is legacy.

What it is

The Server service (srvsvc.dll) in Windows XP SP1 and SP2 fails to properly authenticate an anonymous logon over a named pipe, allowing remote attackers to obtain sensitive information about users accessing resources. This is an information disclosure flaw in a core Windows service, and the record does not specify affected versions beyond XP SP1 and SP2.

Impact

An attacker gains knowledge of which users are accessing resources on the target host, which can support reconnaissance and targeting of accounts. The CVSS vector also lists partial integrity and availability impact, but the description only substantiates the confidentiality loss.

Attack surface

Reachable remotely over the network via the Server service named pipe, with no authentication required (anonymous logon) and no user interaction indicated. The CVSS vector AV:N/AC:L/Au:N is consistent with an unauthenticated remote path.

Exploitation

The record is not listed in CISA KEV and contains no exploit tags, but EPSS shows a 30-day probability of 0.4657 (98.8th percentile), indicating elevated predicted exploitation activity. No public exploit code or in-the-wild use is confirmed by the supplied data.

What to do

  • Apply the Microsoft security update MS05-007 referenced in the record, which is the vendor patch for this flaw.
  • Restrict anonymous access to named pipes and the Server service where operationally feasible.
  • Block SMB/NetBIOS ports (139, 445) at network boundaries and limit lateral reachability of the Server service.
  • Disable or harden the Server service on hosts that do not require file or print sharing.
  • Retire or isolate Windows XP SP1/SP2 systems, which are long past end of support.

Detection

  • Monitor for anonymous logon events (Windows Security event 528/4624 with logon type 3 and null/anonymous account) against the Server service.
  • Alert on named pipe access to srvsvc from unexpected or external source addresses.
  • Baseline and review SMB/NetBIOS connection attempts to hosts running Windows XP.
  • Correlate anonymous SMB sessions with subsequent enumeration of user or share information.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0051 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2013-3918Microsoft Windows InformationCardSigninHelper ActiveX out-of-bounds writeThe InformationCardSigninHelper ActiveX control in icardie.dll contains an out-of-bounds write that can be triggered by a crafted web page rendered i…KEVEPSS 74%analysed8.8CVE-2011-3402Microsoft Windows TrueType Font Parsing Remote Code ExecutionThe TrueType font parsing engine in win32k.sys on multiple Windows versions fails to properly handle crafted font data, allowing remote code executio…KEVEPSS 78%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed7.8CVE-2013-5065Microsoft Windows NDProxy.sys kernel local privilege escalationNDProxy.sys in the Windows kernel on Windows XP SP2/SP3 and Server 2003 SP2 fails to properly validate input, letting a local user escalate privilege…KEVEPSS 35%analysed7.8CVE-2013-3660Microsoft Windows win32k EPATHOBJ pointer flaw allows privilege escalationThe EPATHOBJ::pprFlattenRec function in win32k.sys fails to properly initialize a pointer for the next object in a list, letting a local user gain wr…KEVEPSS 39%analysed7.8CVE-2012-0151Microsoft Windows Authenticode Signature Verification PE Digest Validation FlawThe Authenticode Signature Verification function (WinVerifyTrust) in multiple Microsoft Windows versions fails to properly validate the digest of a s…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2005-0051), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.