Back

CVE-2005-0047

Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (21)

Vendor Product Version
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2003_server enterprise
microsoft windows_2003_server enterprise_64-bit
microsoft windows_2003_server r2
microsoft windows_2003_server r2
microsoft windows_2003_server standard
microsoft windows_2003_server web
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *
microsoft windows_xp *

…and 1 more

GitHub Security Advisory GHSA-4q9j-c8xc-j26g

Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 4.44%

Top 9% most likely to be exploited

Threat Score 30.1 / 100

Data Sources

NVD EPSS GitHub