← Vulnerability feed

Vulnerability record · CVE-2005-2120 · published 13 October 2005

CVE-2005-2120: Windows Plug and Play service stack buffer overflow via registry key name

Microsoft · Windows 2000

The Plug and Play service (UMPNPMGR.DLL) in Windows 2000 SP4 and XP SP1/SP2 contains a stack-based buffer overflow triggered by a registry key name containing a large number of backslash characters, which overflows a wsprintfW call. An authenticated attacker, locally or remotely, can exploit this to run arbitrary code in the service context. The flaw affects core Windows versions and is remotely reachable, making it a serious elevation and code execution risk on unpatched systems.

6.5 CVSS 2.0 Medium EPSS 62% · top 0.8%
6.5CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
30References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote authenticated code execution in a core Windows service with public exploit code and very high EPSS, though limited to legacy unsupported platforms.

What it is

The Plug and Play service (UMPNPMGR.DLL) in Windows 2000 SP4 and XP SP1/SP2 contains a stack-based buffer overflow triggered by a registry key name containing a large number of backslash characters, which overflows a wsprintfW call. An authenticated attacker, locally or remotely, can exploit this to run arbitrary code in the service context. The flaw affects core Windows versions and is remotely reachable, making it a serious elevation and code execution risk on unpatched systems.

Impact

Successful exploitation lets an authenticated attacker execute arbitrary code with the privileges of the PnP service, typically SYSTEM on affected Windows hosts. This can lead to full system compromise, including data theft, persistence, and further lateral movement.

Attack surface

Reached over the network or locally by an authenticated user who can supply a crafted registry key name to the Plug and Play service; no user interaction is required beyond authentication. The CVSS vector AV:N/AC:L/Au:S confirms network reachability with low complexity but single authentication.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.61971, 99th percentile) and a public exploit reference exists (SecurityFocus BID 15065 tagged Exploit), indicating known exploit code is available.

What to do

  • Apply Microsoft security bulletin MS05-047 (or the corresponding vendor patch) to Windows 2000 SP4 and XP SP1/SP2 systems immediately.
  • Upgrade or migrate off Windows 2000 and XP, which are long past end of support and cannot receive current fixes.
  • Restrict network access to the Plug and Play/RPC interfaces to trusted hosts and block unnecessary ports at the perimeter and host firewall.
  • Limit local interactive and remote logon rights so only trusted administrators can authenticate to affected systems.
  • Monitor and audit registry key creation for names containing excessive backslash characters as a compensating control.

Detection

  • Hunt for registry key names containing unusually long runs of backslash characters in PnP-related registry paths.
  • Monitor for unexpected process creation or crashes in services.exe or UMPNPMGR.DLL-related activity on Windows 2000/XP hosts.
  • Review authentication logs for remote logons to legacy Windows systems followed by service instability or unexpected code execution.
  • Use host-based detection to alert on writes to PnP registry keys by non-administrative or unusual accounts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/17166 PatchVendor Advisory
http://secunia.com/advisories/17172
http://secunia.com/advisories/17223
http://securityreason.com/securityalert/71
http://securitytracker.com/id?1015042 Patch
http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf
http://www.eeye.com/html/research/advisories/AD20051011c.html PatchVendor Advisory
http://www.kb.cert.org/vuls/id/214572 Third Party AdvisoryUS Government Resource
http://www.osvdb.org/18830
http://www.securityfocus.com/bid/15065 ExploitPatch
http://www.us-cert.gov/cas/techalerts/TA05-284A.html Third Party AdvisoryUS Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-047
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1244
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1328
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1519
http://secunia.com/advisories/17166 PatchVendor Advisory
http://secunia.com/advisories/17172
http://secunia.com/advisories/17223
http://securityreason.com/securityalert/71
http://securitytracker.com/id?1015042 Patch
http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf
http://www.eeye.com/html/research/advisories/AD20051011c.html PatchVendor Advisory
http://www.kb.cert.org/vuls/id/214572 Third Party AdvisoryUS Government Resource
http://www.osvdb.org/18830
http://www.securityfocus.com/bid/15065 ExploitPatch
http://www.us-cert.gov/cas/techalerts/TA05-284A.html Third Party AdvisoryUS Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-047
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1244
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1328
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1519

Track CVE-2005-2120 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2013-3918Microsoft Windows InformationCardSigninHelper ActiveX out-of-bounds writeThe InformationCardSigninHelper ActiveX control in icardie.dll contains an out-of-bounds write that can be triggered by a crafted web page rendered i…KEVEPSS 74%analysed8.8CVE-2011-3402Microsoft Windows TrueType Font Parsing Remote Code ExecutionThe TrueType font parsing engine in win32k.sys on multiple Windows versions fails to properly handle crafted font data, allowing remote code executio…KEVEPSS 78%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed7.8CVE-2013-5065Microsoft Windows NDProxy.sys kernel local privilege escalationNDProxy.sys in the Windows kernel on Windows XP SP2/SP3 and Server 2003 SP2 fails to properly validate input, letting a local user escalate privilege…KEVEPSS 35%analysed7.8CVE-2013-3660Microsoft Windows win32k EPATHOBJ pointer flaw allows privilege escalationThe EPATHOBJ::pprFlattenRec function in win32k.sys fails to properly initialize a pointer for the next object in a list, letting a local user gain wr…KEVEPSS 39%analysed7.8CVE-2012-0151Microsoft Windows Authenticode Signature Verification PE Digest Validation FlawThe Authenticode Signature Verification function (WinVerifyTrust) in multiple Microsoft Windows versions fails to properly validate the digest of a s…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2005-2120), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.