Local Code Execution Vulnerability in NetDDE Agent on Microsoft Windows
CVE-2002-1230

Currently unrated

What is CVE-2002-1230?

The NetDDE Agent software in multiple versions of Microsoft Windows allows local users to execute arbitrary code at the LocalSystem level through a vulnerability in the handling of WM_TIMER messages. By exploiting this weakness with a specially crafted WM_COPYDATA message followed by a WM_TIMER message, attackers can perform a 'shatter' style attack. This flaw potentially leads to privilege escalation, enabling unauthorized access to system resources.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.