First published: Tue Feb 14 2006(Updated: )
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2003-sp1 | |
Microsoft Office | =2003-sp2 | |
Microsoft Office | =2003 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =web | |
Microsoft Windows 2003 Server | =enterprise | |
Microsoft Windows 2003 Server | =enterprise_64-bit | |
Microsoft Windows XP | =gold | |
Microsoft Windows XP | ||
Microsoft Windows 2003 Server | =standard_64-bit | |
Microsoft Windows 2003 Server | =datacenter_64-bit-sp1 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =r2-sp1 | |
Microsoft Windows 2003 Server | =enterprise_64-bit-sp1 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2003 Server | =web-sp1 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows 2003 Server | =standard-sp1 | |
Microsoft Windows 2003 Server | =enterprise-sp1 | |
Microsoft Windows 2003 Server | =standard | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows 2003 Server | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0008 is considered to have a moderate severity due to the potential for local privilege escalation.
To fix CVE-2006-0008, it is advised to apply the relevant security updates from Microsoft.
CVE-2006-0008 affects local users on Korean versions of Microsoft Windows XP SP1, SP2, Windows Server 2003, and Office 2003.
CVE-2006-0008 is a local privilege escalation vulnerability.
CVE-2006-0008 was disclosed in the year 2006.