CVE-2003-0350

The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*

History

20 Nov 2024, 23:44

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0015.html - Patch, Vendor Advisory () http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0015.html - Patch, Vendor Advisory
References () http://marc.info/?l=bugtraq&m=105777681615939&w=2 - () http://marc.info/?l=bugtraq&m=105777681615939&w=2 -
References () http://www.ngssoftware.com/advisories/utilitymanager.txt - Patch, Vendor Advisory () http://www.ngssoftware.com/advisories/utilitymanager.txt - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/8154 - () http://www.securityfocus.com/bid/8154 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-025 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-025 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/12543 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/12543 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A451 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A451 -

Information

Published : 2003-08-18 04:00

Updated : 2024-11-20 23:44


NVD link : CVE-2003-0350

Mitre link : CVE-2003-0350

CVE.ORG link : CVE-2003-0350


JSON object : View

Products Affected

microsoft

  • windows_2000