CVE-2004-1624 Information
Feb 14, 2021
cve
Description
Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface which allows local users to gain privileges via (1) the help topic interface in CCW32.exe which launches Notepad or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).
Reference
http://marc.info/?l=bugtraq&m=109846296406459&w=2 http://secunia.com/advisories/12962 http://www.securityfocus.com/bid/11500 https://exchange.xforce.ibmcloud.com/vulnerabilities/17838
Share on: