Back

CVE-2004-0213

HIGH

Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.

Published: Aug 6, 2004 Modified: Jun 16, 2026
CWE-306

CVSS Metrics

CVSSv3
Attack Vector: LOCAL Attack Complexity: LOW Privileges Required: LOW User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
microsoft windows_2000 -
microsoft windows_2000 -
microsoft windows_2000 -

GitHub Security Advisory GHSA-62vf-wrg7-5x68

Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with...

Risk Scores

CVSS Score 7.8 / 10
EPSS Score 20.07%

Top 3% most likely to be exploited

Threat Score 37.2 / 100

Data Sources

NVD EPSS GitHub