First published: Wed Jul 14 2004(Updated: )
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2000 | =sp3 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp3 | |
Microsoft Windows 2000 | =sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.