Vulnerability record · CVE-2005-0058 · published 10 August 2005
CVE-2005-0058: Microsoft Windows TAPI buffer overflow via crafted message
Microsoft · Windows 2000
A buffer overflow exists in the Telephony Application Programming Interface (TAPI) on multiple legacy Microsoft Windows versions, including Windows 98, ME, 2000, XP and Server 2003. A crafted message can overflow the buffer, letting an attacker elevate privileges or run arbitrary code. The affected platforms are long out of support, so exposure is limited to systems still running them.
Description
Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to elevate privileges or execute arbitrary code via a crafted message.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw allows unauthenticated remote code execution with a high EPSS score, but it affects only long-unsupported legacy Windows versions, lowering real-world exposure.
What it is
A buffer overflow exists in the Telephony Application Programming Interface (TAPI) on multiple legacy Microsoft Windows versions, including Windows 98, ME, 2000, XP and Server 2003. A crafted message can overflow the buffer, letting an attacker elevate privileges or run arbitrary code. The affected platforms are long out of support, so exposure is limited to systems still running them.
Impact
An attacker can execute arbitrary code or gain elevated privileges on the target host, potentially taking full control of the system.
Attack surface
The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether user interaction is required, so that detail is missing.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.46, ~98.8th percentile), and a vendor patch reference exists, but the record does not confirm public exploit code.
What to do
- Apply the Microsoft security update for MS05-040 (the vendor patch referenced in the record) to all affected systems.
- Retire or isolate hosts still running Windows 98, ME, 2000, XP or Server 2003, as these platforms no longer receive security support.
- Block or restrict network access to TAPI-related services and RPC endpoints on affected hosts using host and perimeter firewalls.
- Disable or remove TAPI components where telephony functionality is not required.
- Monitor for and investigate unexpected code execution or privilege escalation on legacy Windows hosts.
Detection
- Monitor for crashes or abnormal terminations of TAPI-related processes (e.g., telephony service) on affected hosts.
- Alert on unexpected child processes or privilege escalation events originating from TAPI service processes.
- Review network traffic to TAPI/RPC ports on legacy Windows systems for anomalous or malformed messages.
- Use the OVAL definitions referenced in the record to scan for unpatched TAPI components.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0058 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0058), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.