Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).
                
            References
                    | Link | Resource | 
|---|---|
| http://www.kb.cert.org/vuls/id/CRDY-5EXQRP | Third Party Advisory US Government Resource | 
| http://www.kb.cert.org/vuls/id/CRDY-5EXQSV | Third Party Advisory US Government Resource | 
| http://www.kb.cert.org/vuls/id/609137 | Third Party Advisory US Government Resource | 
| http://www.kb.cert.org/vuls/id/231705 | Third Party Advisory US Government Resource | 
| http://www.securityfocus.com/bid/7475 | Patch | 
| http://www.securityfocus.com/bid/7477 | Patch | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/11921 | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/11920 | 
Configurations
                    Information
                Published : 2003-12-30 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2003-1121
Mitre link : CVE-2003-1121
JSON object : View
CWE
                Products Affected
                scriptlogic
- scriptlogic
 


