Vulnerability record · CVE-2005-1984 · published 10 August 2005
CVE-2005-1984: Windows Print Spooler buffer overflow allows remote code execution
Microsoft · Windows 2000
The Print Spooler service (Spoolsv.exe) in Windows 2000, XP, and Server 2003 contains a buffer overflow that can be triggered by a malicious message. Successful exploitation allows remote code execution in the context of the spooler service, which runs with high privileges. This is a network-reachable flaw in a core Windows service, making it significant for unpatched legacy systems.
Description
Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable, unauthenticated remote code execution in a core Windows service with a high EPSS score, though limited to legacy OS versions and not listed in KEV.
What it is
The Print Spooler service (Spoolsv.exe) in Windows 2000, XP, and Server 2003 contains a buffer overflow that can be triggered by a malicious message. Successful exploitation allows remote code execution in the context of the spooler service, which runs with high privileges. This is a network-reachable flaw in a core Windows service, making it significant for unpatched legacy systems.
Impact
A remote attacker can execute arbitrary code on the target host with the privileges of the Print Spooler service, potentially leading to full system compromise. No user interaction is required beyond the service being reachable.
Attack surface
The flaw is reachable over the network via a crafted message to the Print Spooler service, as indicated by the AV:N vector. No authentication is required (Au:N), and no user interaction is needed.
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit references, but EPSS is high (0.55, 98.9th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Apply the Microsoft security update MS05-043 immediately on affected Windows 2000, XP, and Server 2003 systems.
- If patching is not possible, disable or restrict the Print Spooler service on systems that do not require printing.
- Block inbound SMB/RPC traffic to the spooler service at network boundaries where feasible.
- Isolate or upgrade legacy systems that cannot be patched, as these OS versions are no longer supported.
- Monitor vendor and US-CERT advisories for any updated guidance.
Detection
- Monitor for unexpected crashes or restarts of the Spoolsv.exe process.
- Inspect network traffic for anomalous RPC or SMB messages targeting the print spooler service.
- Review Windows event logs for spooler-related errors or unusual service behavior.
- Use host-based detection to flag suspicious child processes spawned by Spoolsv.exe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-1984 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-1984), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.