CVE-2003-0897
Windows XP - Local Privilege Escalation via CommCtl32.dll Button Control Messages
Title source: llmDescription
"Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control messages to privileged applications.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13558
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=106692772510010&w=2
Scores
EPSS
0.0188
EPSS Percentile
77.4%
Details
Status
published
Products (1)
microsoft/windows_xp
Published
Nov 17, 2003
Tracked Since
Feb 18, 2026