← Back

CVE-2006-0008

nvd nist
Published: Feb 14, 2006Modified: Apr 16, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.

Affected (25)

3 products
Office
Windows 2003 Server
Windows Xp
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2003
Version 2003 sp1
Version 2003 sp2
Configuration B
22 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version datacenter_64-bit sp1
Version enterprise
Version enterprise sp1
Version enterprise_64-bit
Version enterprise_64-bit sp1
Version r2
Version r2
Version r2 sp1
Version standard
Version standard sp1
Version standard_64-bit
Version web
Version web sp1
Microsoft
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions

Related CWEs

References (28)

Source: secure@microsoft.com
PatchVendor Advisory
Source: secure@microsoft.com
Patch
Source: secure@microsoft.com
Third Party AdvisoryUS Government Resource
Source: secure@microsoft.com
Vendor Advisory
Source: secure@microsoft.com
Patch
Source: secure@microsoft.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.