Overview
The Microsoft Windows 2000 Utility Manager allows authenticated local users to launch applications with SYSTEM privileges.
Description
| The Microsoft Windows 2000 Utility Manager is a program that permits users to monitor and launch various accessibility applications. This program contains a privilege escalation vulnerability that permits authenticated local users to launch applications with SYSTEM privileges. Microsoft reports that the vulnerability disclosed in MS04-019 is different than the one reported in MS04-011, which is described in VU#526084. | 
Impact
| This vulnerability allows authenticated local users to launch applications with SYSTEM privileges. | 
Solution
| Apply a patch from Microsoft | 
| Disable the Utility Manager 
 | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
This vulnerability was reported to Microsoft by Cesar Cerrudo of Application Security Inc.
This document was written by Jeffrey P. Lanza.
Other Information
| CVE IDs: | CVE-2004-0213 | 
| Severity Metric: | 21.26 | 
| Date Public: | 2004-07-13 | 
| Date First Published: | 2004-07-14 | 
| Date Last Updated: | 2004-07-14 14:37 UTC | 
| Document Revision: | 11 |