COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-051
- https://github.com/ARPSyndicate/cve-scores