The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
| Software | From | Fixed in |
|---|---|---|
| microsoft / windows_2003_server | - | - |
| microsoft / windows_xp | --sp2 | --sp2.x |
| microsoft / windows_xp | --sp3 | --sp3.x |
| microsoft / windows_2000 | - | - |
| microsoft / windows_xp | --gold | --gold.x |
| microsoft / windows_xp | - | - |
| microsoft / windows_xp | sp3-unknown | sp3-unknown.x |
| microsoft / windows_server_2003 | - | - |
| microsoft / windows_xp | --sp1 | --sp1.x |
| microsoft / windows_xp | sp3 | sp3.x |