Vulnerabilities > CVE-2004-2504 - Local Privilege Escalation vulnerability in Alt-N MDaemon
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new files, which allows local users with physical access to gain privileges.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
Nessus
NASL family | SMTP problems |
NASL id | MDAEMON_LOCAL_PRIVILEGES.NASL |
description | It is reported that versions of MDaemon up to and including 7.2.0 are affected by a local privilege escalation vulnerability. An local attacker may increase his privilege and execute code with SYSTEM privileges. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15823 |
published | 2004-11-24 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15823 |
title | MDaemon File Creation Local Privilege Escalation |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2004-11/0385.html
- http://archives.neohapsis.com/archives/fulldisclosure/2004-11/1324.html
- http://archives.neohapsis.com/archives/fulldisclosure/2004-11/1353.html
- http://secunia.com/advisories/13225
- http://securitytracker.com/id?1012350
- http://www.osvdb.org/12158
- http://www.securityfocus.com/bid/11736
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18287