Vulnerability Description
Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell | Client Firewall | 2.0 |
References
- http://secunia.com/advisories/11014Vendor Advisory
- http://securitytracker.com/id?1008755
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/10090585.htmVendor Advisory
- http://www.ciac.org/ciac/bulletins/o-090.shtmlVendor Advisory
- http://www.osvdb.org/4120
- http://www.securityfocus.com/bid/9441
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15367
- http://secunia.com/advisories/11014Vendor Advisory
- http://securitytracker.com/id?1008755
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/10090585.htmVendor Advisory
- http://www.ciac.org/ciac/bulletins/o-090.shtmlVendor Advisory
- http://www.osvdb.org/4120
- http://www.securityfocus.com/bid/9441
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15367
FAQ
What is CVE-2004-2554?
CVE-2004-2554 is a vulnerability with a CVSS score of 7.2 (HIGH). Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help function...
How severe is CVE-2004-2554?
CVE-2004-2554 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2554?
Check the references section above for vendor advisories and patch information. Affected products include: Novell Client Firewall.