Vulnerability record · CVE-2005-2551 · published 12 August 2005
CVE-2005-2551: Novell eDirectory iMonitor dhost.exe buffer overflow
Novell · Edirectory
A buffer overflow exists in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows. The flaw can crash the service and, per the description, allow access to files, though the specific vectors are not documented. It matters because the affected component is remotely reachable and the record gives no detail on the trigger, limiting precise triage.
Description
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated, low-complexity buffer overflow with high EPSS, though no confirmed in-the-wild exploitation or KEV listing.
What it is
A buffer overflow exists in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows. The flaw can crash the service and, per the description, allow access to files, though the specific vectors are not documented. It matters because the affected component is remotely reachable and the record gives no detail on the trigger, limiting precise triage.
Impact
An unauthenticated attacker can cause a denial of service against the iMonitor/dhost service and potentially read files on the host. The description does not specify which files or how far the access extends.
Attack surface
The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether user interaction is required or which port or interface is used.
Exploitation
The record is not listed in CISA KEV and no ransomware use is documented, but EPSS is high at roughly 0.55 (99th percentile), suggesting elevated predicted exploitation activity. No reference is tagged as an exploit, so public exploit code is not confirmed by this record.
What to do
- Apply the Novell vendor patches referenced in the advisory (support.novell.com documents 10098568 and 2972038).
- Restrict network access to the iMonitor/dhost service to trusted management hosts only.
- If patching is not immediately possible, disable or stop the iMonitor service where it is not required.
- Monitor Novell advisories and CERT/CC VU#213165 for updated guidance.
- Run the service with least privilege to limit file access if the overflow is triggered.
Detection
- Monitor dhost.exe for crashes or unexpected restarts in Windows event logs and Novell eDirectory logs.
- Alert on anomalous inbound connections to the iMonitor service from untrusted networks.
- Watch for unusual file read activity by the dhost.exe process outside its normal directories.
- Correlate host-based crash telemetry with network traffic to the iMonitor port.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-2551 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2551), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.