CVE-2004-0213: High severity Microsoft Windows 2000 vulnerability
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0213?
CVE-2004-0213 has a high severity rating due to its potential for local users to escalate privileges and execute arbitrary code.
How do I fix CVE-2004-0213?
To fix CVE-2004-0213, apply the latest security patches provided by Microsoft for Windows 2000.
Who is affected by CVE-2004-0213?
CVE-2004-0213 affects all versions of Windows 2000, including Service Packs 1 through 4.
What is the attack vector for CVE-2004-0213?
CVE-2004-0213 is exploited via a "Shatter" style attack that takes advantage of the Utility Manager's elevated privileges to launch winhlp32.exe.
What are the consequences of exploiting CVE-2004-0213?
Exploiting CVE-2004-0213 allows attackers to gain system privileges, potentially leading to complete control over the affected system.