CVE-2004-0213 describes a privilege escalation vulnerability in the Utility Manager of Microsoft Windows 2000. Local users can exploit this flaw, dubbed a "Shatter" attack, by manipulating the Utility Manager to launch winhlp32.exe with elevated privileges, then instructing winhlp32.exe to open an arbitrary file. This vulnerability carries a high CVSS score of 7.8, indicating a severe risk. It has a low attack complexity and requires no user interaction, allowing an attacker to achieve full confidentiality, integrity, and availability impact (C:H/I:H/A:H) once local access is gained. While not listed on the KEV catalog or Hot List, exploit code for this vulnerability is publicly available on ExploitDB, with multiple entries specifically referencing the Utility Manager privilege escalation. Despite this, there is no recorded community discussion or media coverage, suggesting limited public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:-:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:-:sp3:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:-:sp4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.