PT-2005-3057 · Microsoft · Msdtc

Fang Xing

·

Published

2005-10-11

·

Updated

2018-10-12

·

CVE-2005-2119

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Distributed Transaction Coordinator (MSDTC) (affected versions not specified)
Description: The issue concerns the MIDL user allocate function in the MSDTC proxy, which allocates a fixed size of memory regardless of the actual size required. This allows attackers to potentially overwrite arbitrary memory locations by providing an incorrect size value to the NdrAllocate function, leading to writing management data outside the allocated buffer.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2119

Affected Products

Msdtc