Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6062 | vdb entry |
http://www.securityfocus.com/bid/2341 | vdb entry |
http://www.atstake.com/research/advisories/2001/a020501-1.txt | patch vendor advisory exploit |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-007 | vendor advisory |