CVE-2006-0008: High severity Microsoft Office vulnerability
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0008?
CVE-2006-0008 is considered to have a moderate severity due to the potential for local privilege escalation.
How do I fix CVE-2006-0008?
To fix CVE-2006-0008, it is advised to apply the relevant security updates from Microsoft.
Who is affected by CVE-2006-0008?
CVE-2006-0008 affects local users on Korean versions of Microsoft Windows XP SP1, SP2, Windows Server 2003, and Office 2003.
What type of vulnerability is CVE-2006-0008?
CVE-2006-0008 is a local privilege escalation vulnerability.
When was CVE-2006-0008 disclosed?
CVE-2006-0008 was disclosed in the year 2006.