Oval Definition:oval:org.mitre.oval:def:1046
Revision Date:2004-06-16Version:41
Title:Windows Utility Manager Shatter Message Vulnerability
Description:The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2003-0908
Platform(s):Microsoft Windows 2000
Product(s):Utility Manager
Definition Synopsis
  • Windows 2000 is installed
  • AND the version of umandlg.dll is less than 1.0.0.4
  • AND NOT the patch kb835732 is installed
  • BACK