vendor:
Windows 2000
by:
Cesar Cerrudo
N/A
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Windows 2000
Affected Version From: Windows 2000
Affected Version To: Windows 2000
Patch Exists: NO
Related CWE:
CPE: o:microsoft:windows_2000
Platforms Tested: Windows
Local elevation of privileges exploit for Windows 2K Utility Manager
This exploit allows an attacker to gain system privileges by exploiting the Windows 2K Utility Manager. It gives the attacker a shell with system privileges. The exploit involves finding the Utility Manager window, sending specific messages to open the Open File dialog, setting the text to filter the listview to display only cmd.exe, and sending keystrokes to navigate and select the cmd.exe file. Finally, a context menu is triggered to execute the cmd.exe file with system privileges.
Mitigation:
The recommended mitigation for this vulnerability is to apply the latest security patches and updates provided by the vendor.