PT-2002-2204 · Microsoft · Windows 2000+3
Published
2002-11-04
·
Updated
2019-04-30
·
CVE-2002-1230
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Windows NT 4.0
Windows 4.0 Terminal Server Edition
Windows 2000
Windows XP
Description:
The issue allows local users to execute arbitrary code as LocalSystem via a "shatter" style attack. This is achieved by sending a WM COPYDATA message followed by a WM TIMER message.
Recommendations:
For Windows NT 4.0, apply the necessary patch to fix the flaw in Windows WM TIMER message handling.
For Windows 4.0 Terminal Server Edition, apply the necessary patch to fix the flaw in Windows WM TIMER message handling.
For Windows 2000, apply the necessary patch to fix the flaw in Windows WM TIMER message handling.
For Windows XP, apply the necessary patch to fix the flaw in Windows WM TIMER message handling.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows 2000
Windows Nt 4.0 Terminal Server Edition
Windows Nt 4.0
Windows Xp