Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2006-0008

The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.

  • Published: Feb 14, 2006
  • Updated: Apr 13, 2023
  • CVE: CVE-2006-0008
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.2
  • AV:L/AC:L/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
microsoft / office 2003-sp1 2003-sp1.x
microsoft / office 2003-sp2 2003-sp2.x
microsoft / office 2003 2003.x
microsoft / windows_xp - -
microsoft / windows_2003_server web web.x
microsoft / windows_2003_server enterprise enterprise.x
microsoft / windows_2003_server enterprise_64-bit enterprise_64-bit.x
microsoft / windows_2003_server standard_64-bit standard_64-bit.x
microsoft / windows_2003_server datacenter_64-bit-sp1 datacenter_64-bit-sp1.x
microsoft / windows_2003_server r2-sp1 r2-sp1.x
microsoft / windows_2003_server enterprise_64-bit-sp1 enterprise_64-bit-sp1.x
microsoft / windows_2003_server r2 r2.x
microsoft / windows_2003_server web-sp1 web-sp1.x
microsoft / windows_2003_server standard-sp1 standard-sp1.x
microsoft / windows_2003_server enterprise-sp1 enterprise-sp1.x
microsoft / windows_2003_server standard standard.x