Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-62vf-wrg7-5x68

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.

Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.

EPSS

Процентиль: 84%
0.02315
Низкий

7.8 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.8
nvd
около 21 года назад

Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.

EPSS

Процентиль: 84%
0.02315
Низкий

7.8 High

CVSS3

Дефекты

CWE-306