Vulnerability record · CVE-2005-2120 · published 13 October 2005
CVE-2005-2120: Windows Plug and Play service stack buffer overflow via registry key name
Microsoft · Windows 2000
The Plug and Play service (UMPNPMGR.DLL) in Windows 2000 SP4 and XP SP1/SP2 contains a stack-based buffer overflow triggered by a registry key name containing a large number of backslash characters, which overflows a wsprintfW call. An authenticated attacker, locally or remotely, can exploit this to run arbitrary code in the service context. The flaw affects core Windows versions and is remotely reachable, making it a serious elevation and code execution risk on unpatched systems.
Description
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityRemote authenticated code execution in a core Windows service with public exploit code and very high EPSS, though limited to legacy unsupported platforms.
What it is
The Plug and Play service (UMPNPMGR.DLL) in Windows 2000 SP4 and XP SP1/SP2 contains a stack-based buffer overflow triggered by a registry key name containing a large number of backslash characters, which overflows a wsprintfW call. An authenticated attacker, locally or remotely, can exploit this to run arbitrary code in the service context. The flaw affects core Windows versions and is remotely reachable, making it a serious elevation and code execution risk on unpatched systems.
Impact
Successful exploitation lets an authenticated attacker execute arbitrary code with the privileges of the PnP service, typically SYSTEM on affected Windows hosts. This can lead to full system compromise, including data theft, persistence, and further lateral movement.
Attack surface
Reached over the network or locally by an authenticated user who can supply a crafted registry key name to the Plug and Play service; no user interaction is required beyond authentication. The CVSS vector AV:N/AC:L/Au:S confirms network reachability with low complexity but single authentication.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.61971, 99th percentile) and a public exploit reference exists (SecurityFocus BID 15065 tagged Exploit), indicating known exploit code is available.
What to do
- Apply Microsoft security bulletin MS05-047 (or the corresponding vendor patch) to Windows 2000 SP4 and XP SP1/SP2 systems immediately.
- Upgrade or migrate off Windows 2000 and XP, which are long past end of support and cannot receive current fixes.
- Restrict network access to the Plug and Play/RPC interfaces to trusted hosts and block unnecessary ports at the perimeter and host firewall.
- Limit local interactive and remote logon rights so only trusted administrators can authenticate to affected systems.
- Monitor and audit registry key creation for names containing excessive backslash characters as a compensating control.
Detection
- Hunt for registry key names containing unusually long runs of backslash characters in PnP-related registry paths.
- Monitor for unexpected process creation or crashes in services.exe or UMPNPMGR.DLL-related activity on Windows 2000/XP hosts.
- Review authentication logs for remote logons to legacy Windows systems followed by service instability or unexpected code execution.
- Use host-based detection to alert on writes to PnP registry keys by non-administrative or unusual accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-2120 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2120), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.