CVE-2006-0008
Microsoft Windows XP/Server 2003/Office 2003 - Privilege Escalation
Title source: llmDescription
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
References (14)
Core 14
Core References
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0578
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/16643
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24492
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1688
Patch vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1015631
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/18859
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/739844
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-009
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1595
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A727
Vendor Advisory x_refsource_misc
http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/425141/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1664
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1650
Scores
EPSS
0.0166
EPSS Percentile
74.4%
Details
CWE
CWE-264
Status
published
Products (9)
microsoft/office
2003 (3 CPE variants)
microsoft/windows_2003_server
datacenter_64-bit sp1
microsoft/windows_2003_server
enterprise (2 CPE variants)
microsoft/windows_2003_server
enterprise_64-bit (2 CPE variants)
microsoft/windows_2003_server
r2 (3 CPE variants)
microsoft/windows_2003_server
standard (2 CPE variants)
microsoft/windows_2003_server
standard_64-bit
microsoft/windows_2003_server
web (2 CPE variants)
microsoft/windows_xp
(9 CPE variants)
Published
Feb 14, 2006
Tracked Since
Feb 18, 2026