CVE-2004-1624

Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:altiris:carbon_copy:5.0:*:*:*:*:*:*:*
cpe:2.3:a:altiris:carbon_copy:6.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:51

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=109846296406459&w=2 - () http://marc.info/?l=bugtraq&m=109846296406459&w=2 -
References () http://secunia.com/advisories/12962 - Vendor Advisory () http://secunia.com/advisories/12962 - Vendor Advisory
References () http://www.securityfocus.com/bid/11500 - Vendor Advisory () http://www.securityfocus.com/bid/11500 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/17838 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/17838 -

Information

Published : 2004-10-21 04:00

Updated : 2024-11-20 23:51


NVD link : CVE-2004-1624

Mitre link : CVE-2004-1624

CVE.ORG link : CVE-2004-1624


JSON object : View

Products Affected

altiris

  • carbon_copy