>> Microsoft Windows Plug and Play Remote Code Execution (MS05-047)
Title : Microsoft Windows Plug and Play Remote Code Execution (MS05-047) VUPEN ID : VUPEN/ADV-2005-2044 CVE ID : CVE-2005-2120
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-10-11
Technical Description
A vulnerability has been identified in Microsoft Windows, which may be exploited by attackers to execute abitrary commands or by malicious users to obtain elevated privileges. This issue is due to a buffer overflow error in the Plug and Play (PnP) service that does not properly validate user supplied data to the functions "PNP_GetDeviceList" and "PNP_GetDeviceListSize", which could be exploited by attackers to execute arbitrary commands.
Note : On Windows 2000 and Windows XP SP1, an authenticated user could remotely exploit this vulnerability, however, in certain Windows XP configurations, anonymous users could authenticate and exploit this vulnerability as the Guest account. On Windows XP SP2, only an administrator can remotely access the affected component. Therefore, on Windows XP SP2, this issue is strictly a local privilege elevation vulnerability.