VulnerabilityModified
CVE-2003-0641
WatchGuard ServerLock for Windows 2000 before SL 2.0.3 allows local users to load arbitrary modules via the OpenProcess() function, as demonstrated using (1) a DLL injection attack, (2) ZwSetSystemInformation, and (3) API hooking in OpenProcess.
MEDIUM 4.6EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
WatchGuard ServerLock for Windows 2000 before SL 2.0.3 allows local users to load arbitrary modules via the OpenProcess() function, as demonstrated using (1) a DLL injection attack, (2) ZwSetSystemInformation, and (3) API hooking in OpenProcess.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- watchguard/serverlock
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=105848106631132&w=2
- http://secunia.com/advisories/9310
- http://www.osvdb.org/6578
- http://www.securityfocus.com/bid/8222Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12665
- http://marc.info/?l=bugtraq&m=105848106631132&w=2
- http://secunia.com/advisories/9310
- http://www.osvdb.org/6578
- http://www.securityfocus.com/bid/8222Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12665
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.