CVE-2006-0008 Information

Description

The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2 Windows Server 2003 up to SP1 and Office 2003 allows local users to gain privileges by launching the \shell about dialog box\ and clicking the \End-User License Agreement\ link which executes Notepad with the privileges of the program that displays the about box.

Reference

http://secunia.com/advisories/18859 http://securitytracker.com/id?1015631 http://www.kb.cert.org/vuls/id/739844 http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html http://www.securityfocus.com/archive/1/425141/100/0/threaded http://www.securityfocus.com/bid/16643 http://www.vupen.com/english/advisories/2006/0578 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-009 https://exchange.xforce.ibmcloud.com/vulnerabilities/24492 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1595 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1650 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1664 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1688 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A727

Share on: