The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 00:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/18859 - Patch, Vendor Advisory | |
References | () http://securitytracker.com/id?1015631 - Patch | |
References | () http://www.kb.cert.org/vuls/id/739844 - Third Party Advisory, US Government Resource | |
References | () http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/425141/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/16643 - Patch | |
References | () http://www.vupen.com/english/advisories/2006/0578 - Vendor Advisory | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-009 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/24492 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1595 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1650 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1664 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1688 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A727 - |
Information
Published : 2006-02-14 19:06
Updated : 2024-11-21 00:05
NVD link : CVE-2006-0008
Mitre link : CVE-2006-0008
CVE.ORG link : CVE-2006-0008
JSON object : View
Products Affected
microsoft
- office
- windows_2003_server
- windows_xp
CWE
CWE-264
Permissions, Privileges, and Access Controls