CVE-2004-2504
Summary
| CVE | CVE-2004-2504 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new files, which allows local users with physical access to gain privileges. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Alt-n | Mdaemon | 6.8.0 | All | All | All |
| Application | Alt-n | Mdaemon | 6.8.1 | All | All | All |
| Application | Alt-n | Mdaemon | 6.8.2 | All | All | All |
| Application | Alt-n | Mdaemon | 6.8.3 | All | All | All |
| Application | Alt-n | Mdaemon | 6.8.4 | All | All | All |
| Application | Alt-n | Mdaemon | 6.8.5 | All | All | All |
| Application | Alt-n | Mdaemon | 7.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Alt-N MDaemon Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| archives.neohapsis.com/archives/fulldisclosure/2004-11/1353.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Secunia - Advisories - MDaemon New File Creation Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| archives.neohapsis.com/archives/bugtraq/2004-11/0385.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit |
| SecurityTracker.com Archives - MDaemon System Tray Icon Lets Local Users Gain System Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit |
| www.osvdb.org/12158 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| archives.neohapsis.com/archives/fulldisclosure/2004-11/1324.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.