CVE-2004-0213

HIGH

Microsoft Windows 2000 - Missing Authentication

Title source: rule

Description

Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.

Exploits (4)

exploitdb WORKING POC VERIFIED
by bkbll · clocalwindows
https://www.exploit-db.com/exploits/351
exploitdb WORKING POC VERIFIED
by kralor · clocalwindows
https://www.exploit-db.com/exploits/352
exploitdb WORKING POC VERIFIED
by Cesar Cerrudo · clocalwindows
https://www.exploit-db.com/exploits/350
exploitdb WORKING POC VERIFIED
by kralor · clocalwindows
https://www.exploit-db.com/exploits/355

Scores

CVSS v3 7.8
EPSS 0.0239
EPSS Percentile 84.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-306
Status draft

Affected Products (3)

microsoft/windows_2000
microsoft/windows_2000
microsoft/windows_2000

Timeline

Published Aug 06, 2004
Tracked Since Feb 18, 2026