peter bassill · operator
$ cve CVE-2003-0908 JSON

CVE-2003-0908 EXPLOIT

7.2
HIGH · CVSS 2.0 · EPSS 25.9% (pctl 98)

Patch early

A public exploit exists.

Description

The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.

Scoring

CVSS7.2 (HIGH, v2.0)
VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS25.94% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2004-06-01
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftwindows 2000

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD