First published: Thu Jul 10 2003(Updated: )
The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2000 | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0350 is considered a high-severity vulnerability due to the potential for local users to execute arbitrary code.
To mitigate CVE-2003-0350, users should apply the latest security patches for Windows 2000 and consider restricting local user access.
CVE-2003-0350 affects Microsoft Windows 2000, including all service packs like SP1, SP2, and SP3.
Local users with access to the system can exploit CVE-2003-0350 to execute arbitrary code.
CVE-2003-0350 relates to a local privilege escalation attack via a 'Shatter' style message.