PT-2003-1554 · Microsoft · Windows 2000

Chris Paget

·

Published

2003-07-10

·

Updated

2019-04-30

·

CVE-2003-0350

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Windows 2000
Description: The issue concerns the Accessibility Utility Manager on Windows, where the control for listing accessibility options does not properly handle Windows messages. This allows local users to execute arbitrary code via a specific style message to the Utility Manager that references a user-controlled callback function, known as a "Shatter" style message.
Recommendations: For Windows 2000, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0350

Affected Products

Windows 2000