CVE-2004-2663
The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.95% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- ibm/egatherer
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=108746693619324&w=2
- http://marc.info/?l=full-disclosure&m=108741557604568&w=2
- http://research.eeye.com/html/advisories/published/AD20040615B.html
- http://secunia.com/advisories/11072
- http://www.eeye.com/html/research/advisories/AD20040615B.htmlExploit, Patch, Vendor Advisory
- http://www.osvdb.org/7090
- http://www.securityfocus.com/bid/10562
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16428
- http://marc.info/?l=bugtraq&m=108746693619324&w=2
- http://marc.info/?l=full-disclosure&m=108741557604568&w=2
- http://research.eeye.com/html/advisories/published/AD20040615B.html
- http://secunia.com/advisories/11072
- http://www.eeye.com/html/research/advisories/AD20040615B.htmlExploit, Patch, Vendor Advisory
- http://www.osvdb.org/7090
- http://www.securityfocus.com/bid/10562
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16428
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.