First published: Wed Aug 09 2006(Updated: )
Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2000 | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3443 is classified as a high-severity vulnerability due to its potential to allow local users to gain elevated privileges.
To fix CVE-2006-3443, ensure that SafeDllSearchMode is enabled or update to a patched version of Microsoft Windows that addresses this vulnerability.
CVE-2006-3443 affects Microsoft Windows 2000, specifically versions with Service Pack 1 to 4.
CVE-2006-3443 enables local users to execute a malicious DLL to gain elevated privileges within the system.
While CVE-2006-3443 primarily affects outdated systems, it remains a threat to any systems still running unpatched versions of Windows 2000.