CVE-2006-0008

The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
References
Link Resource
http://secunia.com/advisories/18859 Patch Vendor Advisory
http://securitytracker.com/id?1015631 Patch
http://www.kb.cert.org/vuls/id/739844 Third Party Advisory US Government Resource
http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html Vendor Advisory
http://www.securityfocus.com/archive/1/425141/100/0/threaded
http://www.securityfocus.com/bid/16643 Patch
http://www.vupen.com/english/advisories/2006/0578 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-009
https://exchange.xforce.ibmcloud.com/vulnerabilities/24492
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1595
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1650
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1664
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1688
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A727
http://secunia.com/advisories/18859 Patch Vendor Advisory
http://securitytracker.com/id?1015631 Patch
http://www.kb.cert.org/vuls/id/739844 Third Party Advisory US Government Resource
http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html Vendor Advisory
http://www.securityfocus.com/archive/1/425141/100/0/threaded
http://www.securityfocus.com/bid/16643 Patch
http://www.vupen.com/english/advisories/2006/0578 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-009
https://exchange.xforce.ibmcloud.com/vulnerabilities/24492
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1595
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1650
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1664
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1688
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A727
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:office:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:r2:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*

History

21 Nov 2024, 00:05

Type Values Removed Values Added
References () http://secunia.com/advisories/18859 - Patch, Vendor Advisory () http://secunia.com/advisories/18859 - Patch, Vendor Advisory
References () http://securitytracker.com/id?1015631 - Patch () http://securitytracker.com/id?1015631 - Patch
References () http://www.kb.cert.org/vuls/id/739844 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/739844 - Third Party Advisory, US Government Resource
References () http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html - Vendor Advisory () http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html - Vendor Advisory
References () http://www.securityfocus.com/archive/1/425141/100/0/threaded - () http://www.securityfocus.com/archive/1/425141/100/0/threaded -
References () http://www.securityfocus.com/bid/16643 - Patch () http://www.securityfocus.com/bid/16643 - Patch
References () http://www.vupen.com/english/advisories/2006/0578 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/0578 - Vendor Advisory
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-009 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-009 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/24492 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/24492 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1595 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1595 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1650 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1650 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1664 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1664 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1688 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1688 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A727 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A727 -

Information

Published : 2006-02-14 19:06

Updated : 2024-11-21 00:05


NVD link : CVE-2006-0008

Mitre link : CVE-2006-0008

CVE.ORG link : CVE-2006-0008


JSON object : View

Products Affected

microsoft

  • office
  • windows_2003_server
  • windows_xp
CWE
CWE-264

Permissions, Privileges, and Access Controls