Back

CVE-2005-0044

The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (25)

Vendor Product Version
microsoft exchange_server 5.0
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2003_server enterprise
microsoft windows_2003_server enterprise_64-bit
microsoft windows_2003_server r2
microsoft windows_2003_server r2
microsoft windows_2003_server standard
microsoft windows_2003_server web
microsoft windows_98 *
microsoft windows_98se *
microsoft windows_me *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *

…and 5 more

GitHub Security Advisory GHSA-m4w4-9m3w-pg34

The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003,...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 33.36%

Top 2% most likely to be exploited

Threat Score 40 / 100

Data Sources

NVD EPSS GitHub