Vulnerabilities > CVE-2003-0350 - Unspecified vulnerability in Microsoft Windows 2000

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
microsoft
nessus

Summary

The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.

Vulnerable Configurations

Part Description Count
OS
Microsoft
4

Nessus

  • NASL familyWindows : Microsoft Bulletins
    NASL idSMB_NT_MS03-025.NASL
    descriptionThe remote host runs a version of Windows that has a flaw in the way the utility manager handles Windows messages. As a result, it is possible for a local user to gain additional privileges on this host.
    last seen2020-06-01
    modified2020-06-02
    plugin id11789
    published2003-07-13
    reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11789
    titleMS03-025: Flaw in Windows Message Handling through Utility Manager Could Enable Privilege Elevation (822679)
  • NASL familyWindows
    NASL idSERVICE_PACK_NOT_INSTALLED.NASL
    descriptionThe remote version of Microsoft Windows has no service pack or the one installed is no longer supported. As a result, it is likely to contain security vulnerabilities.
    last seen2020-06-02
    modified2007-10-05
    plugin id26921
    published2007-10-05
    reporterThis script is Copyright (C) 2007-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/26921
    titleWindows Service Pack Out-of-Date

Oval

accepted2011-05-16T04:03:00.883-04:00
classvulnerability
contributors
  • nameChristine Walzer
    organizationThe MITRE Corporation
  • nameChristine Walzer
    organizationThe MITRE Corporation
  • nameShane Shaffer
    organizationG2, Inc.
  • nameSudhir Gandhe
    organizationTelos
  • nameShane Shaffer
    organizationG2, Inc.
descriptionThe control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.
familywindows
idoval:org.mitre.oval:def:451
statusaccepted
submitted2003-09-09T12:00:00.000-04:00
titleWindows ListView Shatter Message Vulnerability
version70