Vulnerability record · CVE-2005-1983 · published 10 August 2005
CVE-2005-1983: Microsoft Windows Plug and Play Service Stack Buffer Overflow
Microsoft · Windows 2000
The Plug and Play (PnP) service in Windows 2000 and Windows XP SP1 contains a stack-based buffer overflow that can be triggered by a crafted packet. The flaw allows remote code execution and was exploited in the Zotob/Mytob worm, making it a high-impact, wormable vulnerability.
Description
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10.0, wormable remote code execution, and very high EPSS probability make this an urgent risk despite not being in CISA KEV.
What it is
The Plug and Play (PnP) service in Windows 2000 and Windows XP SP1 contains a stack-based buffer overflow that can be triggered by a crafted packet. The flaw allows remote code execution and was exploited in the Zotob/Mytob worm, making it a high-impact, wormable vulnerability.
Impact
A remote attacker can execute arbitrary code with system privileges, and a local user can gain elevated privileges via a malicious application. Successful exploitation can lead to full system compromise.
Attack surface
The vulnerability is reachable over the network via a crafted packet to the PnP service, requiring no authentication or user interaction. Local privilege escalation is possible through a malicious application.
Exploitation
The description states it was exploited by the Zotob (aka Mytob) worm. It is not listed in CISA KEV, but EPSS probability is 0.93014 (99.8th percentile), indicating very high likelihood of exploitation activity.
What to do
- Apply the Microsoft security update MS05-039 immediately.
- Disable the Plug and Play service if not required, or restrict network access to it.
- Block TCP ports 445 and 139 at the network perimeter and between internal segments.
- Upgrade affected systems from Windows 2000 and Windows XP SP1 to supported versions.
- Monitor for worm-like propagation and anomalous SMB traffic.
Detection
- Monitor for unexpected crashes or restarts of the Plug and Play service.
- Inspect network traffic for crafted packets targeting the PnP service on SMB ports.
- Look for signs of Zotob/Mytob worm activity, such as mass scanning or file creation.
- Audit systems for missing MS05-039 patch using vulnerability scanners.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-1983 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-1983), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.