Vulnerability record · CVE-2005-0308 · published 24 January 2005
CVE-2005-0308: W32Dasm wsprintf buffer overflow via import/export names
Ursoftware · W32dasm
W32Dasm 8.93 and earlier contains a buffer overflow in the wsprintf function that is triggered by an oversized import or export function name. Because the tool is used to disassemble untrusted binaries, opening a crafted executable can crash the application or run attacker code in the context of the user running W32Dasm.
Description
Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export function name.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe CVSS 2.0 score is 7.5 (HIGH) and EPSS is 0.66 at the 99.2nd percentile, but the record shows no KEV listing or confirmed public exploit.
What it is
W32Dasm 8.93 and earlier contains a buffer overflow in the wsprintf function that is triggered by an oversized import or export function name. Because the tool is used to disassemble untrusted binaries, opening a crafted executable can crash the application or run attacker code in the context of the user running W32Dasm.
Impact
An attacker who supplies a malicious binary can execute arbitrary code with the privileges of the W32Dasm user, potentially leading to full compromise of the workstation.
Attack surface
The flaw is reached remotely over the network (AV:N) with no authentication and no user interaction beyond loading the crafted file into W32Dasm, per the CVSS 2.0 vector AV:N/AC:L/Au:N.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.65861, 99.2nd percentile), indicating elevated predicted exploitation activity; the only reference tag present is Vendor Advisory, so no public exploit code is confirmed in the record.
What to do
- Upgrade W32Dasm to a version later than 8.93 if one is available; the record does not name a fixed version, so verify with the vendor.
- If no patch exists, stop using W32Dasm to open untrusted or externally sourced binaries.
- Run W32Dasm in a sandboxed or low-privilege environment isolated from production data.
- Apply application allowlisting and endpoint controls so only trusted binaries are opened in analysis tools.
Detection
- Monitor for W32Dasm process crashes or abnormal child processes spawned from W32Dasm.
- Alert on W32Dasm loading binaries from email attachments, downloads or removable media.
- Use EDR to flag code execution or memory corruption behavior originating from W32Dasm.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0308 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2005-0308), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.