PT-2006-1104 · Microsoft · Windows Xp+3

Ryan Lee

·

Publicado

2006-02-14

·

Atualizado

2018-10-30

·

CVE-2006-0008

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Windows XP versions SP1 through SP2 Microsoft Windows Server 2003 versions up to SP1 Microsoft Office 2003
Description: The issue concerns the ShellAbout API call in the Korean Input Method Editor (IME) in certain Microsoft products. It allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link. This action executes Notepad with the privileges of the program displaying the about box.
Recommendations: For Microsoft Windows XP versions SP1 through SP2, consider restricting access to the ShellAbout API call until a fix is available. For Microsoft Windows Server 2003 versions up to SP1, avoid using the Korean Input Method Editor (IME) until the issue is resolved. For Microsoft Office 2003, as a temporary workaround, consider disabling the launch of the "shell about dialog box" to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-0008

Produtos afetados

Office 2003
Windows Server 2003
Windows Xp
Notepad++