PT-2002-2204 · Microsoft · Windows 2000+3

Published

2002-11-04

·

Updated

2019-04-30

·

CVE-2002-1230

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Windows NT 4.0 Windows 4.0 Terminal Server Edition Windows 2000 Windows XP
Description: The issue allows local users to execute arbitrary code as LocalSystem via a "shatter" style attack. This is achieved by sending a WM COPYDATA message followed by a WM TIMER message.
Recommendations: For Windows NT 4.0, apply the necessary patch to fix the flaw in Windows WM TIMER message handling. For Windows 4.0 Terminal Server Edition, apply the necessary patch to fix the flaw in Windows WM TIMER message handling. For Windows 2000, apply the necessary patch to fix the flaw in Windows WM TIMER message handling. For Windows XP, apply the necessary patch to fix the flaw in Windows WM TIMER message handling.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1230

Affected Products

Windows 2000
Windows Nt 4.0 Terminal Server Edition
Windows Nt 4.0
Windows Xp