← Vulnerability feed

Vulnerability record · CVE-2005-1984 · published 10 August 2005

CVE-2005-1984: Windows Print Spooler buffer overflow allows remote code execution

Microsoft · Windows 2000

The Print Spooler service (Spoolsv.exe) in Windows 2000, XP, and Server 2003 contains a buffer overflow that can be triggered by a malicious message. Successful exploitation allows remote code execution in the context of the spooler service, which runs with high privileges. This is a network-reachable flaw in a core Windows service, making it significant for unpatched legacy systems.

7.5 CVSS 2.0 High EPSS 55% · top 1.0%
7.5CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated remote code execution in a core Windows service with a high EPSS score, though limited to legacy OS versions and not listed in KEV.

What it is

The Print Spooler service (Spoolsv.exe) in Windows 2000, XP, and Server 2003 contains a buffer overflow that can be triggered by a malicious message. Successful exploitation allows remote code execution in the context of the spooler service, which runs with high privileges. This is a network-reachable flaw in a core Windows service, making it significant for unpatched legacy systems.

Impact

A remote attacker can execute arbitrary code on the target host with the privileges of the Print Spooler service, potentially leading to full system compromise. No user interaction is required beyond the service being reachable.

Attack surface

The flaw is reachable over the network via a crafted message to the Print Spooler service, as indicated by the AV:N vector. No authentication is required (Au:N), and no user interaction is needed.

Exploitation

The record does not list this CVE in CISA KEV and provides no exploit references, but EPSS is high (0.55, 98.9th percentile), suggesting elevated likelihood of exploitation activity.

What to do

  • Apply the Microsoft security update MS05-043 immediately on affected Windows 2000, XP, and Server 2003 systems.
  • If patching is not possible, disable or restrict the Print Spooler service on systems that do not require printing.
  • Block inbound SMB/RPC traffic to the spooler service at network boundaries where feasible.
  • Isolate or upgrade legacy systems that cannot be patched, as these OS versions are no longer supported.
  • Monitor vendor and US-CERT advisories for any updated guidance.

Detection

  • Monitor for unexpected crashes or restarts of the Spoolsv.exe process.
  • Inspect network traffic for anomalous RPC or SMB messages targeting the print spooler service.
  • Review Windows event logs for spooler-related errors or unusual service behavior.
  • Use host-based detection to flag suspicious child processes spawned by Spoolsv.exe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-1984 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2013-3918Microsoft Windows InformationCardSigninHelper ActiveX out-of-bounds writeThe InformationCardSigninHelper ActiveX control in icardie.dll contains an out-of-bounds write that can be triggered by a crafted web page rendered i…KEVEPSS 74%analysed8.8CVE-2011-3402Microsoft Windows TrueType Font Parsing Remote Code ExecutionThe TrueType font parsing engine in win32k.sys on multiple Windows versions fails to properly handle crafted font data, allowing remote code executio…KEVEPSS 78%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed7.8CVE-2015-1701Microsoft Windows Win32k.sys Local Privilege EscalationWin32k.sys in the Windows kernel-mode drivers fails to properly validate input, allowing a local user to elevate privileges by running a crafted appl…KEVEPSS 56%analysed7.8CVE-2013-5065Microsoft Windows NDProxy.sys kernel local privilege escalationNDProxy.sys in the Windows kernel on Windows XP SP2/SP3 and Server 2003 SP2 fails to properly validate input, letting a local user escalate privilege…KEVEPSS 35%analysed7.8CVE-2013-3660Microsoft Windows win32k EPATHOBJ pointer flaw allows privilege escalationThe EPATHOBJ::pprFlattenRec function in win32k.sys fails to properly initialize a pointer for the next object in a list, letting a local user gain wr…KEVEPSS 39%analysed

Source: NIST National Vulnerability Database (record CVE-2005-1984), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.