Privilege Escalation in ScriptLogic 4.01 and Earlier Versions

Privilege Escalation in ScriptLogic 4.01 and Earlier Versions

CVE-2003-1121 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).

Learn more about our Cis Benchmark Audit For Server Software.