First published: Sat Oct 16 2004(Updated: )
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | =4.0 | |
Microsoft Windows 2000 | ||
Microsoft Windows Server 2003 | =r2 | |
Microsoft Windows 9x | =gold | |
Microsoft Windows XP | =gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0207 is considered to have a high severity due to the potential for privilege escalation by local users.
To remediate CVE-2004-0207, users should upgrade to a supported version of Windows that does not contain this vulnerability.
CVE-2004-0207 affects Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003.
CVE-2004-0207 is a local vulnerability and cannot be exploited remotely; an attacker must have local access to the system.
CVE-2004-0207 allows local users to escalate privileges, potentially enabling them to execute unauthorized actions in the system.