// For flags

CVE-2003-0641

 

Severity Score

4.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

WatchGuard ServerLock for Windows 2000 before SL 2.0.3 allows local users to load arbitrary modules via the OpenProcess() function, as demonstrated using (1) a DLL injection attack, (2) ZwSetSystemInformation, and (3) API hooking in OpenProcess.

WatchGuard ServerLock para Windows 2000 anteriores a SL 2.0.3 permite a usuarios locales cargar ficheros arbitrarios mediante la función OpenProcess(), como ha sido demostrado usando (1) un ataque de inyección de DLL, (2) ZwSetSystemInformation, y (3) una función API enganchada a OpenProcess.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2003-08-01 CVE Reserved
  • 2003-08-02 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Watchguard
Search vendor "Watchguard"
Serverlock
Search vendor "Watchguard" for product "Serverlock"
2.0
Search vendor "Watchguard" for product "Serverlock" and version "2.0"
-
Affected
Watchguard
Search vendor "Watchguard"
Serverlock
Search vendor "Watchguard" for product "Serverlock"
2.0.1
Search vendor "Watchguard" for product "Serverlock" and version "2.0.1"
-
Affected
Watchguard
Search vendor "Watchguard"
Serverlock
Search vendor "Watchguard" for product "Serverlock"
2.0.2
Search vendor "Watchguard" for product "Serverlock" and version "2.0.2"
-
Affected