peter bassill · operator
$ cve CVE-2005-0063 JSON

CVE-2005-0063 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 47.6% (pctl 99)

Patch early

A public exploit exists.

Description

The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS47.65% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2005-05-02
Last modified2026-06-16

Affected (6)

VendorProduct
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows 98
microsoftwindows 98se
microsoftwindows me
microsoftwindows xp

Public exploits

SourceTitleDate
exploit-dbMicrosoft Windows - 'HTA' Script Execution (MS05-016)2005-04-14

References

→ the Explorer  ·  watch your stack  ·  NVD