VDB
CVE-2006-0008
CVE-2006-0008
PUBLISHED
CVSS 7.199999809265137 HIGH
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
EPSS 0.79% · 74.2th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.79%
74.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_2003_server | web, *, * |
| microsoft | windows_xp | |
| microsoft | office | 2003, 2003, 2003 |
| n/a | n/a | n/a |
Timeline
- Feb 14, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- oval:org.mitre.oval:def:1688 vdb
- ADV-2006-0578 vdb
- 16643 vdb
- win-korean-ime-privilege-elevation(24492) vdb
- 1015631 vdb
- 18859 third-party-advisory
- VU#739844 third-party-advisory
- MS06-009 vendor-advisory
- oval:org.mitre.oval:def:1595 vdb
- oval:org.mitre.oval:def:727 vdb
- http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html url
- 20060215 Security advisory: Windows IME Vulnerability (MS06-009) mailing-list
- oval:org.mitre.oval:def:1664 vdb
- oval:org.mitre.oval:def:1650 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2006-0008 advisory