Vulnerability record · CVE-2005-1218 · published 10 August 2005
CVE-2005-1218: Windows kernel RDP request denial of service
Microsoft · Windows 2000
The Microsoft Windows kernel in Windows 2000 Server, Windows XP, and Windows Server 2003 fails to properly handle crafted Remote Desktop Protocol (RDP) requests, allowing a remote attacker to crash the system. The flaw matters because RDP is commonly exposed for remote administration, and a crash of the kernel takes down the whole host, not just a single service.
Description
The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityUnauthenticated remote network access that crashes the kernel, with a very high EPSS score, though the affected platforms are long out of support and no active exploitation is documented.
What it is
The Microsoft Windows kernel in Windows 2000 Server, Windows XP, and Windows Server 2003 fails to properly handle crafted Remote Desktop Protocol (RDP) requests, allowing a remote attacker to crash the system. The flaw matters because RDP is commonly exposed for remote administration, and a crash of the kernel takes down the whole host, not just a single service.
Impact
An attacker gains the ability to cause a denial of service, crashing the affected Windows system. There is no reported confidentiality or integrity impact; the effect is availability loss.
Attack surface
Reached over the network via RDP requests to the target host, per the AV:N vector. The CVSS vector indicates no authentication (Au:N) and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is high (0.57339, 99th percentile), but references carry only Patch, Vendor Advisory, and US Government Resource tags, with no public exploit tag, so active exploitation is not confirmed by this record.
What to do
- Apply the Microsoft security update for MS05-041 (referenced advisory 904797) to affected Windows 2000 Server, XP, and Server 2003 systems.
- Restrict RDP exposure to trusted networks and block TCP 3389 from untrusted sources at the perimeter.
- Require RDP access through a VPN or jump host rather than direct internet exposure.
- Disable or remove Terminal Services/RDP on hosts that do not need it.
- Monitor vendor advisories for these end-of-life platforms, since no further fixes are expected.
Detection
- Monitor for repeated RDP connection attempts or malformed RDP traffic preceding a host crash or unexpected reboot.
- Alert on Windows system event logs showing unexpected shutdowns or bugchecks on hosts with RDP enabled.
- Baseline RDP source IPs and flag connections from unexpected external addresses to TCP 3389.
- Correlate host crash/reboot events with concurrent RDP session activity on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-1218 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-1218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.