Back

CVE-2005-0050

The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."

Published: May 2, 2005 Modified: Jun 16, 2026
CWE-20

CVSS Metrics

Affected Products (37)

Vendor Product Version
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2003_server 2000
microsoft windows_2003_server 2003
microsoft windows_2003_server enterprise
microsoft windows_2003_server enterprise_64-bit
microsoft windows_2003_server r2
microsoft windows_2003_server r2
microsoft windows_2003_server standard
microsoft windows_2003_server web
microsoft windows_nt 4.0
microsoft windows_nt 4.0
microsoft windows_nt 4.0
microsoft windows_nt 4.0
microsoft windows_nt 4.0
microsoft windows_nt 4.0
microsoft windows_nt 4.0

…and 17 more

GitHub Security Advisory GHSA-xh84-5f5q-96wv

The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 46.69%

Top 1% most likely to be exploited

Threat Score 54 / 100

Data Sources

NVD EPSS GitHub