CVE-2003-1121
Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.17% probability · 90th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/231705Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/609137Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/CRDY-5EXQRPThird Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/CRDY-5EXQSVThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/7475Patch
- http://www.securityfocus.com/bid/7477Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11920
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11921
- http://www.kb.cert.org/vuls/id/231705Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/609137Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/CRDY-5EXQRPThird Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/CRDY-5EXQSVThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/7475Patch
- http://www.securityfocus.com/bid/7477Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11920
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11921
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.