CVE-2004-0213

HIGH

Microsoft Windows 2000 - Missing Authentication

Title source: rule

Description

Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.

Exploits (4)

exploitdb WORKING POC VERIFIED
by kralor · clocalwindows
https://www.exploit-db.com/exploits/355
exploitdb WORKING POC VERIFIED
by kralor · clocalwindows
https://www.exploit-db.com/exploits/352
exploitdb WORKING POC VERIFIED
by bkbll · clocalwindows
https://www.exploit-db.com/exploits/351
exploitdb WORKING POC VERIFIED
by Cesar Cerrudo · clocalwindows
https://www.exploit-db.com/exploits/350

Scores

CVSS v3 7.8
EPSS 0.0236
EPSS Percentile 85.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (1)
microsoft/windows_2000 (3 CPE variants)
Published Aug 06, 2004
Tracked Since Feb 18, 2026