CVE-2006-3443: High severity Microsoft Windows 2000 vulnerability
Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3443?
CVE-2006-3443 is classified as a high-severity vulnerability due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2006-3443?
To fix CVE-2006-3443, ensure that SafeDllSearchMode is enabled or update to a patched version of Microsoft Windows that addresses this vulnerability.
What systems are affected by CVE-2006-3443?
CVE-2006-3443 affects Microsoft Windows 2000, specifically versions with Service Pack 1 to 4.
What type of attack does CVE-2006-3443 enable?
CVE-2006-3443 enables local users to execute a malicious DLL to gain elevated privileges within the system.
Is CVE-2006-3443 still a threat today?
While CVE-2006-3443 primarily affects outdated systems, it remains a threat to any systems still running unpatched versions of Windows 2000.