Back

CVE-2003-0908

The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.

Published: Jun 1, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
microsoft windows_2000 *

GitHub Security Advisory GHSA-wwxr-4g98-3vf6

The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 25.94%

Top 2% most likely to be exploited

Threat Score 36.6 / 100

Data Sources

NVD EPSS GitHub