Skip to main content

CVE-2005-2119

5.0
CVSS v2.0 Base Score
59.35%
MEDIUM RiskEPSS (98th percentile)
NVD-CWE-Other

The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.

Published: 10/12/2005
Modified: 4/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

5

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Score (Exploitation Probability)

59.35%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 59.35% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

CWE Classification

NVD-CWE-Other