View Definition

Definition Id: oval:org.mitre.oval:def:1046 Version: 1  Last Modified: 2004-04-14
Title: Windows Utility Manager Shatter Message Vulnerability
Description: The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.
Family: windows Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2003-0908
Platform(s): Microsoft Windows 2000 Product(s): Utility Manager
Definition Synopsis: