CVE-2005-1208 describes an integer overflow vulnerability in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier. This flaw allows remote attackers to execute arbitrary code by crafting a malicious compiled Help (.CHM) file with an oversized field, leading to a heap-based buffer overflow. With a CVSS score of 10.0, this vulnerability is critical, requiring no authentication and having low attack complexity, potentially resulting in complete compromise of confidentiality, integrity, and availability. While the EPSS score is low, indicating infrequent exploitation, there is no public exploit intelligence available, and it has not garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:* | ||
64-bitCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:64-bit:*:*:*:*:*:*:* | ||
datacenter_64-bitCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:* | ||
datacenter_64-bitCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1_beta_1:*:*:*:*:*:* | ||
enterpriseCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.