Overview
The Microsoft Windows 2000 Utility Manager allows authenticated local users to launch applications with SYSTEM privileges.
Description
The Microsoft Windows 2000 Utility Manager is a program that permits users to monitor and launch various accessibility applications. This program contains a privilege escalation vulnerability that permits authenticated local users to launch applications with SYSTEM privileges. Microsoft reports that the vulnerability disclosed in MS04-019 is different than the one reported in MS04-011, which is described in VU#526084. |
Impact
This vulnerability allows authenticated local users to launch applications with SYSTEM privileges. |
Solution
Apply a patch from Microsoft |
Disable the Utility Manager
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported to Microsoft by Cesar Cerrudo of Application Security Inc.
This document was written by Jeffrey P. Lanza.
Other Information
CVE IDs: | CVE-2004-0213 |
Severity Metric: | 21.26 |
Date Public: | 2004-07-13 |
Date First Published: | 2004-07-14 |
Date Last Updated: | 2004-07-14 14:37 UTC |
Document Revision: | 11 |