Windows ListView Shatter Message VulnerabilityID: oval:org.mitre.oval:def:451 | Date: (C)2003-09-09 (M)2018-02-19 |
Class: VULNERABILITY | Family: windows |
The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.
Platform: |
Microsoft Windows 2000 |
Product: |
Utilities Manager/Windows Messaging |