4.6
CVSSv2

CVE-2002-1230

Published: 04/11/2002 Updated: 30/04/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 510
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 2000

microsoft windows 2000 terminal services

Exploits

source: wwwsecurityfocuscom/bid/5927/info The Winlogon NetDDE Agent can be leveraged to allow local privilege escalation This is related to the Microsoft Windows Window Message Subsystem Design Error Vulnerability (BID 5408) A local user can use a WM_COPYDATA message to send arbitrary code to NetDDE, which will be executed with Local S ...
source: wwwsecurityfocuscom/bid/5408/info A serious design error in the Win32 API has been reported The issue is related to the inter-window message passing system This vulnerability is wide-ranging and likely affects almost every Win32 window-based application Attackers with local access may exploit this vulnerability to elevate pr ...
source: wwwsecurityfocuscom/bid/5408/info A serious design error in the Win32 API has been reported The issue is related to the inter-window message passing system This vulnerability is wide-ranging and likely affects almost every Win32 window-based application Attackers with local access may exploit this vulnerability to elevate priv ...
source: wwwsecurityfocuscom/bid/5408/info A serious design error in the Win32 API has been reported The issue is related to the inter-window message passing system This vulnerability is wide-ranging and likely affects almost every Win32 window-based application Attackers with local access may exploit this vulnerability to elevat ...
source: wwwsecurityfocuscom/bid/5408/info A serious design error in the Win32 API has been reported The issue is related to the inter-window message passing system This vulnerability is wide-ranging and likely affects almost every Win32 window-based application Attackers with local access may exploit this vulnerability to elevate privi ...
source: wwwsecurityfocuscom/bid/5408/info A serious design error in the Win32 API has been reported The issue is related to the inter-window message passing system This vulnerability is wide-ranging and likely affects almost every Win32 window-based application Attackers with local access may exploit this vulnerability to elevate p ...
source: wwwsecurityfocuscom/bid/5408/info A serious design error in the Win32 API has been reported The issue is related to the inter-window message passing system This vulnerability is wide-ranging and likely affects almost every Win32 window-based application Attackers with local access may exploit this vulnerability to elevate ...
source: wwwsecurityfocuscom/bid/5927/info The Winlogon NetDDE Agent can be leveraged to allow local privilege escalation This is related to the Microsoft Windows Window Message Subsystem Design Error Vulnerability (BID 5408) A local user can use a WM_COPYDATA message to send arbitrary code to NetDDE, which will be executed with Local Sy ...
source: wwwsecurityfocuscom/bid/5408/info A serious design error in the Win32 API has been reported The issue is related to the inter-window message passing system This vulnerability is wide-ranging and likely affects almost every Win32 window-based application Attackers with local access may exploit this vulnerability to elevate pri ...
source: wwwsecurityfocuscom/bid/5408/info A serious design error in the Win32 API has been reported The issue is related to the inter-window message passing system This vulnerability is wide-ranging and likely affects almost every Win32 window-based application Attackers with local access may exploit this vulnerability to elevate ...